Skip to content
Quantum Secure Labs
Cybersecurity News

FortiBleed is still active: FBI warns of attacks on FortiGate firewalls using stolen credentials

The FBI and the US Secret Service warn that FortiBleed is still active: attackers are getting into Fortinet FortiGate firewalls and SSL VPNs with stolen or reused credentials, sometimes locking administrators out. If…

By Quantum Secure Labs4 min read
Firewall de red con cables conectados en un rack de servidores de una oficina
In this article

The FBI and the US Secret Service warn that FortiBleed is still active: attackers are getting into Fortinet FortiGate firewalls and SSL VPNs with stolen or reused credentials, sometimes locking administrators out. If your company runs one, today change passwords, kill active sessions, turn on MFA and take the admin interface off the internet.

Key facts

  • The FBI and the Secret Service (USSS) issued a joint advisory on Tuesday 6 October: FortiBleed remains an active threat to internet-facing Fortinet FortiGate firewalls and SSL VPN gateways (The Hacker News).
  • SOCRadar counts around 86,644 confirmed compromised devices across 194 countries. That is a count of compromised devices, not an estimate of exposure (SecurityWeek).
  • The campaign began in June. SOCRadar has confirmed at least 12 ransomware deployments stemming from this access, with hundreds of machines encrypted, and links it to the INC and Lynx groups.
  • In some incidents the attacker creates admin accounts and uses them to delete the original ones or change their passwords, locking victims out of their own firewall (BleepingComputer).
  • This is not a bug a patch will fix: the way in is weak, reused or leaked credentials.

How do they get in if it isn't a software bug?

With passwords that are already out there. According to the agencies, the campaign exploits reused or leaked credentials and legacy SHA-256 password storage, which allows authentication data to be harvested and cracked at scale.

The Hacker News describes a five-stage attack chain:

  1. Reconnaissance of exposed VPN and admin portals.
  2. Credential stuffing and password spraying using earlier breaches and infostealer logs (malware that steals passwords from browsers).
  3. Installation of a tool called FortigateSniffer on the device.
  4. Offline hash cracking on a GPU cluster.
  5. Data theft from file shares and lateral movement across the network.

A Russian-speaking initial access broker is suspected: someone who breaks in and then sells that access to ransomware groups.

Am I affected if my FortiGate is managed by a provider?

Yes, you can be. Someone else managing it doesn't change the fact that the device sits on your network and it's your data that gets encrypted. You're exposed if you have an internet-facing FortiGate or Fortinet SSL VPN and any of these is true: admin or VPN passwords that haven't been changed in a long time, passwords shared with other services, a VPN without a second factor, or an admin panel open to the internet.

Warning signs: admin accounts nobody recognises, passwords that suddenly stop working, or VPN logins at odd hours.

What to do today

  1. Check, or have someone check, that the FortiGate admin interface is not reachable from the internet.
  2. Terminate all active VPN and admin sessions.
  3. Reset admin and VPN passwords. Make them unique and not used anywhere else.
  4. Enable phishing-resistant MFA on the VPN and on admin access.
  5. Review local and API accounts. Remove any nobody can explain and go through the access logs.
  6. Ask for admin passwords to be stored with PBKDF2, as the agencies recommend (SecurityWeek).
  7. Ask your IT provider to confirm in writing that all of the above has been done.

If you can no longer log into the firewall or you find unknown accounts, treat it as an intrusion. Notify INCIBE-CERT and an incident response team. According to Huntress, patching isn't enough at that point: a factory reset and rebuild of the device may be needed.

What it means for a small business

The firewall is the front door to your network. This campaign doesn't exploit anything clever: it uses passwords that were already floating around. That's bad news, because waiting for a patch won't help, and good news, because what stops it is in your hands and takes an afternoon.

The real risk is false comfort along the lines of "the firmware is up to date". If the credentials are already compromised, updating changes nothing. And time matters: the access is sold to ransomware groups, so every day the door stays open is another day for someone to buy it.

If an outside provider runs your FortiGate, don't assume they've already checked. Ask in writing, with a date. If you're not sure who manages your perimeter or how, now is a good time to sort it out; our cybersecurity for small businesses work covers exactly this.

Frequently asked questions

Is updating the FortiGate firmware enough?

No. FortiBleed uses stolen or reused credentials, not a software bug. You need to change passwords, kill sessions, enable MFA and review accounts.

What do I do if I can't get into my firewall any more?

Treat it as an intrusion: notify INCIBE-CERT and an incident response team. A factory reset and rebuild of the device may be necessary.

Why should I care about a warning from the US?

Because the 86,644 compromised devices SOCRadar counts are spread across 194 countries. The campaign goes after any exposed FortiGate, wherever it is.

Sources

Worried about a threat like this one?

We review your exposure and show you how to protect yourself.

See our cybersecurity service

Cybersecurity News

Attackers are exploiting critical CVE-2026-21589 in Jira and Confluence Data Center

Since 7 October, attackers have been trying to exploit CVE-2026-21589, a critical flaw that lets anyone read files without authentication in eight self-hosted Atlassian Data Center products, including Jira, Confluence…

Cybersecurity News

A malicious spreadsheet can run code in LibreOffice and OpenOffice; only LibreOffice has a patch

A malicious spreadsheet can run an attacker's code in LibreOffice and Apache OpenOffice as soon as it is opened, with no macro warning, if Java is enabled. It affects any company using these suites. Update LibreOffice…

Cybersecurity News

Warlock ransomware keeps breaching unpatched on-premises SharePoint and targets Spanish-speaking countries

Symantec warns that the Warlock ransomware group is still breaking into unpatched on-premises SharePoint servers and has hit organisations in Spanish- and Portuguese-speaking countries, including in Europe. If your…

Want to apply these ideas to your business?

Tell us about your case and we'll show you how to apply these strategies to your project.