FortiBleed campaign compromising 86,000 FortiGate firewalls
21
Views

Imagine coming to work and finding out that the firewall protecting your office no longer accepts your password. In fact, someone else changed it last night. For thousands of companies, that isn’t a nightmare. It’s FortiBleed, a credential-stealing campaign that has quietly taken over more than 86,000 Fortinet FortiGate devices worldwide.

On 6 October 2026, the FBI and the US Secret Service issued a joint warning about it. So, let’s break down what it is, how it works and what you should do today.

⚡ FortiBleed: Quick Facts

  • What: A large credential-theft campaign against FortiGate firewalls and SSL VPN gateways
  • Scale: 86,000+ compromised devices in 194 countries
  • Warning: Joint FBI and US Secret Service advisory, 6 October 2026
  • Patch? No. It abuses weak and reused passwords, not a software bug

What Is FortiBleed?

It’s the name for a long-running hacking campaign that targets internet-facing Fortinet FortiGate firewalls and VPN gateways. Specifically, these boxes sit at the edge of company networks. In other words, they decide who gets in.

Unlike many attacks, this one doesn’t depend on a new software bug. Instead, the attackers log in with real usernames and passwords. As a result, a normal security patch does not stop it.

Security agencies have warned about it for months. For example, the US cyber agency CISA and the UK’s NCSC raised the alarm back in June 2026.

How the FortiBleed Attack Works

According to the FBI and Secret Service advisory, the attack follows a simple but effective chain:

  1. Scan: Automated scripts look for FortiGate VPN login pages on the internet.
  2. Guess: Attackers try leaked and reused passwords (credential stuffing) and common passwords across many accounts (password spraying).
  3. Crack: They steal password hashes and crack them offline, at scale.
  4. Stay in: They create new admin accounts. Sometimes, they also delete or change the real admin accounts, so the owner gets locked out.
  5. Sell: Finally, they sort victims by revenue and sell the access to ransomware gangs.

Interestingly, the whole operation came to light because the hackers exposed their own backend server. As a result, that mistake revealed their internal workflow to researchers.

FortiBleed attack chain from scanning to ransomware access

Why FortiBleed Is So Dangerous

  • It’s huge. SOCRadar verified 86,644 compromised devices across 194 countries.
  • It feeds ransomware. The agencies say the access has helped affiliates of the INC/Lynx and Payload ransomware groups get in.
  • It can lock you out. Because attackers change admin passwords, you may lose control of your own firewall.
  • Patching alone won’t help. After all, the attackers use valid logins, not a bug.

Many Indian businesses, colleges and hospitals use FortiGate firewalls too. Therefore, IT teams in India should treat this warning just as seriously as teams in the US or UK.

What To Do About FortiBleed Right Now

Based on the advisory and expert guidance, here’s a practical checklist:

  • Kill all sessions. First, end every admin and VPN session on the device.
  • Reset every password. Use long, unique passwords, and never reuse them anywhere else.
  • Turn on MFA. Multi-factor authentication makes stolen passwords far less useful.
  • Check for strange accounts. Remove any admin or VPN user nobody recognizes.
  • Hide the admin page. Don’t expose firewall management to the internet at all.
  • Plan for a lockout. Set up console or out-of-band access before you need it.

If you followed my post on the Denmark CPR data breach, you’ll notice the same lesson again. Trusted access, not clever hacking, is often the real weak spot.

🎮 Quick Quiz: Test Yourself

Now, let’s see how much you remember. Try to get all six right!

Key Takeaways

  • The campaign has compromised 86,000+ FortiGate devices in 194 countries.
  • It uses stolen and reused passwords, so a patch won’t fix it.
  • Stolen access gets sold to ransomware groups such as INC/Lynx and Payload.
  • Reset credentials, enable MFA and hide the admin interface today.

Frequently Asked Questions (FAQ)

1. Is this a software vulnerability?

No. It’s a credential-theft campaign. Attackers log in with stolen or guessed passwords, so there’s no CVE to patch.

2. How many devices are affected?

So far, SOCRadar has verified 86,644 compromised FortiGate devices across 194 countries.

3. Who issued the latest warning?

The FBI and the US Secret Service released a joint advisory on 6 October 2026.

4. Will updating my FortiGate firmware stop it?

Updating is always good practice. However, it won’t stop the campaign on its own. You also need to reset credentials, enable MFA and remove unknown accounts.

Sources

Article Categories:
Information Security

Leave a Reply

Your email address will not be published. Required fields are marked *