Identity
FortiBleed: FBI says FortiGate credential theft continues
The FBI and Secret Service say FortiBleed is still locking admins out of FortiGate firewalls and feeding ransomware. How it works and what to check.
The FBI and the US Secret Service published a joint advisory on October 6, JCSA-20261006-01, warning that the FortiBleed campaign against Fortinet FortiGate firewalls and SSL VPN gateways is still active. The attackers log in with stolen or cracked passwords, add their own administrator accounts, and in some cases delete the real ones so the owner is locked out of their own firewall. The agencies say the access has been handed on to ransomware affiliates, including INC/Lynx and Payload.
If you run an internet-facing FortiGate, this affects you whatever firmware you run, because FortiBleed uses no CVE. Fortinet's position is that it is not a new vulnerability: the attackers use credentials from earlier leaks, infostealer logs and brute force. That means a fully patched firewall with a reused or weakly stored admin password is still exposed, and a patch alone does not evict anyone already inside.
How it works
The campaign starts with credentials that already exist somewhere: passwords from earlier Fortinet leaks, logins scraped from infostealer malware on staff laptops, and guesses from password spraying (trying a few common passwords across many accounts) and credential stuffing (replaying leaked username and password pairs). Any login that works on the SSL VPN portal or the web admin interface gets the attackers onto the device.
From there, the weak point is how older FortiOS releases store admin passwords. Before FortiOS 7.2.11, 7.4.8 and 7.6.1, admin passwords were stored as SHA-256 hashes, which are fast to compute and so fast to crack on graphics cards. Those releases switched to PBKDF2, a deliberately slow hashing scheme with random salts, but an upgrade does not convert existing passwords. Each admin's hash stays SHA-256 until that admin logs in again, and Fortinet keeps the previous SHA-256 value in a hidden old-password field for backward compatibility, which shows up in any configuration backup a super_admin takes.
So a stolen config file is a list of crackable hashes. Reporting on the advisory and earlier research describes the operators cracking them offline with Hashcat, managed across a GPU cluster with Hashtopolis, an open-source tool for spreading cracking jobs over many machines. A cracked admin password opens the device again later, even after the VPN password that got them in has been changed.
What attackers are doing
The advisory says the activity it describes was observed between June 18 and July 23, 2026, and that scanning is continuing. Once in, the operators create administrator accounts with names chosen to look like Fortinet services. Names reported from the advisory include fortiAdmin, forticloud-sync, support_fortinet and system_config. The agencies warn that matching names is not enough, because names change: check every account against your own records.
SOCRadar, which named the campaign, has documented a tool it calls FortigateSniffer that runs the built-in diagnose sniffer packet command to capture authentication traffic for protocols such as RADIUS, NTLM, Kerberos and LDAP passing through the firewall. That turns one compromised firewall into a source of domain credentials for the network behind it. Files left on the attackers' own server included Active Directory enumeration scripts, and SOCRadar describes the group as an initial access broker that sells or passes footholds to ransomware crews.
The size of the campaign depends on who is counting:
CISA's June 18 alert cited leaked credentials for about 74,000 Fortinet devices. SOCRadar's later count is 86,644 compromised devices in 194 countries, and that is the figure most coverage of the October advisory repeats. SOCRadar has separately reported remote access attempts against more than 430,000 FortiGate targets, which some outlets round to 400,000 or more. That number counts devices the infrastructure tried, not devices it got into, and should not be read as the number compromised.
What to do
Work through these in order. Start on the firewalls that expose SSL VPN or admin access to the internet.
- Take admin access off the internet. The advisory ranks the options: trusted hosts on each admin account is good, a local-in policy that limits who can reach the management ports is better, and no internet-facing administration at all is best.
- End every session, then reset every password. Terminate all active admin and VPN sessions before the reset, or an attacker keeps the session they already have. Fortinet's CLI reference documents
get system admin listto show who is logged in (some builds useget system admin-list) andexecute disconnect-admin-session <index>to drop a session. Then reset all admin and VPN passwords, and treat any Active Directory or LDAP account used on the firewall as exposed too. - Get every admin hash onto PBKDF2. Upgrade to FortiOS 7.2.11, 7.4.8, 7.6.1 or later and set a new password for every admin from a super_admin account. To clear the stored SHA-256 values, CSA Singapore and Arctic Wolf point to a setting under
config system password-policy. In 7.6 it islogin-lockout-upon-weaker-encryption; on 7.2 and 7.4 sources disagree on the name, so runset ?there and check Fortinet's notes for your build first. Enabling it locks admins out if you later downgrade to firmware without PBKDF2 support. - Require phishing-resistant multi-factor authentication on admin and VPN accounts, meaning FIDO2 keys or certificates rather than codes that can be relayed.
- Audit REST API keys. The advisory asks for unknown API keys to be removed and legitimate ones regenerated, since an API key keeps working after passwords change.
Check whether you were already hit
- List every administrator and every local VPN user, and compare them with your records. Any account nobody can explain is a finding, whatever its name.
- Compare the running config with a known-good backup. Look for new admins, changed trusted hosts, new local-in or firewall policies, and changes to VPN settings.
- Review admin and VPN login events in the FortiGate system event logs, and in your log collector if they are forwarded there, for logins from unfamiliar addresses and bursts of failures. Field names and menu paths vary by version, so check Fortinet's log reference.
- Look for use of
diagnose sniffer packetyou did not run, and for outbound connections from the firewall to addresses you do not recognise. - If you find unauthorized changes, Fortinet's guidance is to treat the device as compromised and follow its recovery process. The agencies point to CISA's eviction playbooks and ask for reports to the FBI's IC3 or CISA.
Why a patched firewall can still be open
Most teams track firewall risk by firmware version, and FortiBleed slips past that measure. The questions that would have caught it are about identity on the device: which accounts exist, how their passwords are stored, where admin logins are accepted from and whether anyone reviews them. A quarterly review of admin accounts and management exposure on every edge device is worth as much as staying current on firmware.
Our network penetration tests check whether firewall admin and VPN portals can be reached and logged into from the internet, and our attack surface management work keeps that list current as devices change. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: The Hacker News, The Register, Security Affairs, Security Boulevard (SafeBreach), Help Net Security, CyberScoop, Cybersecurity Dive, BleepingComputer on the CISA alert, BleepingComputer on FortigateSniffer, Dark Reading, Arctic Wolf, CSA Singapore, CloudSEK, Fortinet CLI reference: disconnect-admin-session, Fortinet CLI reference: system admin list, Fortinet 7.6 administration guide.