The FBI and U.S. Secret Service warned that FortiBleed remains an active global credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Attackers use stolen credentials, credential harvesting, and brute-force attacks against devices with weak passwords and no multifactor authentication. They create administrator accounts, disable or delete legitimate accounts, and change passwords to lock owners out while maintaining persistence and attempting lateral movement. SOCRadar initially verified 86,644 compromised devices across 194 countries and later estimated that the wider operation targeted approximately 400,000–450,000 firewalls; those figures represent different measures of campaign scope.
Initial access brokers have used FortiBleed compromises to supply access to ransomware affiliates associated with INC/Lynx and Payload, turning gateway intrusions into potential enterprise ransomware incidents. The agencies warned that patching and password resets alone may be insufficient. Organizations should restrict internet-facing management access, terminate active sessions, reset administrative and VPN passwords, enforce strong passwords and phishing-resistant MFA, audit accounts and logs for unauthorized changes, and secure credential storage.

Map this exposure pattern across your cloud, code, and identities.
11 events from the most recent confirmed update back to the earliest known activity.
The FBI issued an advisory with the U.S. Secret Service warning that FortiBleed attackers manipulate administrator accounts to maintain access and lock out legitimate users, and that intrusions have provided initial access to INC/Lynx and Payload ransomware affiliates. The advisory included indicators of compromise and recommended restricting internet-facing administration, terminating sessions, resetting credentials, and enforcing phishing-resistant MFA.
CISA issued a FortiBleed warning alongside U.K. officials three months before the FBI and Secret Service advisory.
FortiBleed was first reported as a credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Attackers used credential harvesting and brute-force attacks against devices with weak passwords and no multifactor authentication.
Researchers at threat-modeling.com reportedly described attackers combining stolen FortiBleed VPN credentials with exploitation of CVE-2026-39813 in FortiSandbox to obtain code execution and enable lateral movement.
SecurityWeek reports that the FortiBleed campaign was attributed to a Russian initial access broker. The article does not identify the broker by name or specify when the attribution occurred.
FortiBleed operators accidentally exposed their backend infrastructure through an open directory, allowing investigators to examine target selection, credential verification, and preparation of compromised access for sale. The investigation revealed GPU-accelerated password cracking using Hashcat and Hashtopolis and prioritization of targets by revenue and network structure.
SOCRadar reported in July that it had observed at least 12 confirmed ransomware attacks stemming from FortiBleed, documenting realized ransomware impact beyond compromised firewall and VPN access.
SOCRadar CISO Ensar Seker said a later investigation identified approximately 400,000–450,000 firewalls targeted by the wider operation. He cautioned that this targeting estimate and the initial compromised-device count measured different aspects of the campaign and were not directly comparable.
SOCRadar's initial investigation verified 86,644 compromised devices across 194 countries, establishing the campaign's global reach.
CSIRT Italia analyzed files released by the FortiBleed actor and identified evidence involving Italian assets and organizations in a dataset concerning Internet-exposed Fortinet/FortiGate SSL-VPN devices. The report did not name individual victims.
The reference identified Oracle, Comcast and Samsung as organizations involved in the FortiBleed credential-harvesting campaign exposed in June. The campaign leaked thousands of enterprise-level sign-in details.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
23 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourceinfosecurity-magazine.com
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourceacn.gov.it
Open sourcesdxcentral.com
Open sourceattack.mitre.org
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.