Four months after it first surfaced, FortiBleed hasn’t gone away. It has grown teeth. On October 6, 2026, the FBI and the U.S. Secret Service warned that the FortiBleed credential-compromise campaign against Fortinet FortiGate firewalls and SSL VPN gateways is still active, with more than 86,000 devices compromised across 194 countries. The short version: attackers aren’t exploiting a new bug, they’re logging in with stolen, reused or cracked passwords, then selling that access to ransomware gangs.
If your company runs a FortiGate, or you connect to work through a FortiClient VPN, this one is worth ten minutes of your time. Here’s what’s happening, who’s really exposed, and the exact steps to lock things down.
FortiBleed at a glance
| Detail | What we know |
|---|---|
| What it is | A global credential-harvesting and access-selling campaign against internet-facing FortiGate firewalls and SSL VPN gateways |
| New vulnerability? | No. Fortinet says it is not a new flaw; it abuses weak, reused or leaked credentials |
| Scale (latest) | 86,644+ compromised devices in 194 countries, per SOCRadar figures cited by the FBI |
| Main techniques | Credential stuffing, password spraying, offline cracking of legacy SHA-256 hashes, rogue admin accounts |
| Who buys the access | Ransomware affiliates, including INC/Lynx and Payload |
| Latest warning | Joint FBI and Secret Service advisory, October 6, 2026 |
| Top fixes | Kill sessions, reset passwords, phishing-resistant MFA, take admin access off the internet, upgrade to PBKDF2 hashing |
What is FortiBleed, exactly?
FortiBleed is the name researchers gave to a huge cache of FortiGate admin and SSL VPN credentials, plus the criminal operation behind it. It came to light in June 2026 when security researcher Bob Diachenko found an exposed server apparently belonging to the attackers, complete with tooling and harvested logins. According to Recorded Future, the dataset allegedly covered about 73,932 FortiGate firewall URLs across 194 countries and more than 21,600 domains.
Sounds like a classic hack, right? Not quite. Nobody broke the firewall’s code. The attackers went after the front door with keys they’d collected, guessed or cracked.
Fortinet was clear on this point. In its June 19 PSIRT analysis, the company said the activity “is not a new Fortinet vulnerability” and pointed to reused credentials from earlier incidents plus brute-force attacks on devices with weak password hygiene and no multi-factor authentication. The key takeaway here is simple: there’s no patch that magically fixes FortiBleed. Your passwords and your settings are the fix.
Why the FBI’s FortiBleed warning matters now
Here’s the thing. Plenty of breaches flare up in the headlines and fade within weeks. This one did the opposite. The joint FBI and Secret Service advisory (JCSA-20261006-01), titled “FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts,” says attackers are still scanning exposed FortiGate devices and that the access has become an entry point for ransomware affiliates.
That word “lockouts” is the scary part. According to Cybersecurity Dive, attackers create their own admin accounts and, in many cases, delete or change the passwords on the original ones, so the legitimate owners can’t get back into their own firewall. SOCRadar has also counted at least 12 confirmed ransomware deployments tied to this access, encrypting hundreds of endpoints.
“FortiBleed should be treated as an active access operation, not as a one-time credential leak.” – Ensar Seker, CISO at SOCRadar, speaking to The Hacker News
FortiBleed timeline: from leak to FBI advisory
Let’s back up a little. The story has moved fast, and the device counts have shifted as researchers verified more data. Here’s how it unfolded.
| Date (2026) | What happened |
|---|---|
| June 7 | Recorded Future’s Insikt Group spots suspicious activity from infrastructure later tied to the campaign |
| June 13 | Bob Diachenko publicly reports the dataset; Hudson Rock validates parts of it and releases a lookup tool |
| June 18 | CISA urges FortiGate customers to harden devices, per the Cloud Security Alliance |
| June 19 | Fortinet publishes its analysis: not a new vulnerability, credential reuse and brute force |
| June 20 | Cloud Security Alliance research note flags default accounts and leftover SHA-256 hashes |
| June 24 | Recorded Future details roughly 73,932 affected FortiGate URLs |
| July 1 | SOCRadar links FortiBleed to INC Ransom and Lynx ransomware operations |
| October 6 | FBI and Secret Service warn the campaign is still active: 86,644+ devices, 194 countries |
Why the jump from roughly 74,000 to over 86,000? Different researchers measured different things at different times. Recorded Future counted firewall URLs in the leaked dataset, while SOCRadar’s figure counts verified compromised devices. Either way, the scale is enormous.
How the FortiBleed attacks work
The FBI advisory describes a chain that looks more like a business process than a smash-and-grab:
- Scanning: automated searches for FortiGate SSL VPN and admin login pages exposed to the internet.
- Credential stuffing and spraying: trying usernames and passwords from old leaks and infostealer logs, or a few common passwords across many accounts.
- Offline cracking: stealing password hashes and cracking them on a rented GPU cluster, which works best against older SHA-256 hashes.
- Persistence: creating new admin accounts with names like fortiAdmin, forticloud-sync or support_fortinet that look official at a glance.
- Resale: sorting victims by revenue and network value, then selling the access as an initial-access broker.
That SHA-256 detail matters more than it sounds. According to the Cloud Security Alliance, Fortinet started moving admin passwords to stronger PBKDF2 hashing in FortiOS 7.2.11, 7.4.8 and 7.6.1. Here’s the catch: the upgrade only applied once an admin logged in after updating, and old hashes could linger in a hidden field inside configuration backups. So a firewall you thought was modern could still give up a crackable password.
The CSA also found that default and generic accounts made up about 63% of the compromised credentials. If your firewall still has an account called admin with a password nobody’s touched in years, you’re exactly the kind of target this campaign hunts for.
Who’s at risk from FortiBleed?
This isn’t only a big-enterprise problem. Researchers say the campaign hit government, telecom, healthcare, finance, manufacturing and energy, and the FBI-cited reporting puts India, the U.S., Taiwan, Mexico and Turkey among the hardest-hit countries. But the profile of a likely victim is more about habits than size.
- Small and mid-sized businesses: often run a single FortiGate set up years ago by an outside IT provider, with the admin page still reachable from the internet and no MFA.
- Managed service providers: one weak, shared admin password can open dozens of client networks at once.
- Remote and hybrid workers: if your company VPN runs on FortiGate, your VPN login is a target. A password reused from another site can be enough.
- Schools, local government and clinics: lean IT teams and older hardware make legacy settings more likely.
What about home users? A typical home router isn’t a FortiGate, so FortiBleed doesn’t target your living room directly. The risk reaches you through work: your company VPN account, or your personal data sitting on a breached employer’s network, much like we saw with the Oracle Health data breach.
How to tell if your FortiGate has been compromised
You see, the danger with credential attacks is that they look like normal logins. Still, there are tell-tale signs. Fortinet, the FBI and Beazley Security all point to the same checks:
- Unknown admin accounts: compare every account against what you expect. The FBI lists 19 names seen in the wild, including adminin, fgtsecure, roadmin, itadmin and forti_support2.
- Odd logins: successful admin or SSL VPN logins from unfamiliar countries, IP ranges or hours.
- Config changes: new VPN users, unexpected password resets, unexplained configuration exports or backups.
- Lockouts: if you suddenly can’t log in to your own firewall, treat that as an emergency, not a glitch.
- Downstream activity: strange logins or new accounts on domain controllers, Active Directory or SQL servers.
Found something? Assume the device is compromised. Isolate it, preserve the logs, and bring in your incident response team or IT provider before you start deleting things.
How to protect against FortiBleed: 7 steps
Let’s break it down. These steps follow the FBI advisory and Fortinet’s own guidance, ordered so the fastest wins come first. Using an outside IT provider? Send them this list.
1. End every active admin and VPN session
Kick everyone out first. If an attacker is already logged in with a stolen session, a password change alone won’t remove them. Terminating sessions forces everyone, including any intruder, to sign in again.
2. Reset every admin and VPN password
Change all administrator and VPN passwords, starting with internet-facing devices and generic accounts like admin. Use long, unique passwords per device, and never reuse one from another service.
3. Turn on phishing-resistant MFA
The FBI specifically calls for phishing-resistant multi-factor authentication on all remote access and admin accounts. The CSA notes that SMS codes and push prompts can still be abused, so hardware keys or certificate-based options are the stronger choice.
4. Take admin access off the public internet
Fortinet frames this as good, better, best: restrict management to trusted hosts (good), use a local-in policy (better), or remove internet administration entirely (best). If nobody on the internet can reach your login page, stolen passwords are far less useful.
5. Upgrade FortiOS and switch to PBKDF2 hashing
Fortinet recommends moving to the latest 7.4, 7.6 or 8.0 releases, which store admin credentials with PBKDF2. After upgrading, make sure admins log in and change passwords so old SHA-256 hashes are replaced, and remove legacy password settings.
6. Audit accounts, API keys and configuration
Compare your current setup with a known-good backup. Delete accounts you don’t recognize, review all REST API keys, and restrict who can access existing configuration backups, since they may still hold crackable hashes.
7. Review logs and report anything suspicious
Check firewall, VPN, authentication and domain controller logs for unusual access. If you find evidence of compromise, the FBI asks you to report it to IC3, your local FBI or Secret Service field office, or CISA at 1-844-Say-CISA.
“A firewall is only as strong as its weakest admin password.”
FortiBleed vs. the FortiMail flaw: not the same problem
If you’ve been following Fortinet news, you might be mixing this up with the FortiMail vulnerability (CVE-2026-104286) covered here recently. They’re different issues. FortiMail is Fortinet’s email security product, and that story is about a software flaw you fix by patching.
| FortiBleed | FortiMail CVE-2026-104286 | |
|---|---|---|
| Product | FortiGate firewalls and SSL VPN | FortiMail email gateway |
| Root cause | Stolen, reused or cracked credentials | Software vulnerability |
| Main fix | Reset passwords, MFA, lock down admin access | Apply Fortinet’s patch |
| Does patching alone help? | No | Yes, as the core step |
That said, the lesson overlaps with other edge-device stories, like the Citrix NetScaler vulnerability: anything sitting on your network’s edge is a magnet for attackers, whether they use a bug or a password.
What to do next about FortiBleed
The good news? FortiBleed is beatable with basics you control today. You don’t need to wait for a vendor patch, and you don’t need a huge budget. You need fresh passwords, real MFA and an admin page the internet can’t see.
Fast forward a few months, and the organizations that act this week will be the ones that never show up in a ransomware leak post. If you run IT, block out an hour today and work through the seven steps. If you’re an employee on a company VPN, change that password, make sure it isn’t used anywhere else, and enable whatever MFA option your IT team offers. Groups like ShinyHunters have shown how quickly stolen access gets monetized, so the sooner you close the door, the better.
Frequently asked questions
It collects working logins for internet-facing Fortinet FortiGate firewalls and SSL VPNs, then uses or sells that access. Ransomware affiliates, including INC/Lynx and Payload, have bought it to break into company networks.
It’s a credential problem. Fortinet says it is not a new vulnerability. Attackers rely on reused, leaked, weak or cracked passwords, especially on accounts without MFA and on devices still storing older SHA-256 password hashes.
Look for admin accounts you didn’t create, logins from unusual locations or times, new VPN users, unexpected password resets or config exports, and any sudden lockout from your own device. Hudson Rock also released a lookup tool to check whether a domain appears in the leaked data.
Not directly, since home routers aren’t FortiGate firewalls. The risk for most people is indirect: your work VPN login, or your data stored on a business network that gets breached through a compromised firewall.
No. Upgrading to a release that uses PBKDF2 hashing helps, but you still need to reset passwords, end active sessions, add phishing-resistant MFA and remove admin access from the internet.
Isolate the device, keep the logs, and contact your IT or incident response provider and Fortinet support. The FBI also asks victims to report to IC3, a local FBI or Secret Service field office, or CISA.
