Threats · Credential Abuse

FBI and Secret Service Warn FortiBleed Campaign Still Locking Admins Out of FortiGates

A joint advisory says the global FortiBleed campaign remains active against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways — and that compromised organizations may need remediation well beyond patching and password resets.

A Fortinet FortiGate 6501F firewall appliance
A FortiGate 6501F firewall appliance. The FortiBleed campaign targets internet-facing FortiGate firewalls and SSL VPN gateways.

Photo: Premeditated, CC BY-SA 4.0, via Wikimedia Commons

The Federal Bureau of Investigation and the U.S. Secret Service issued a joint cybersecurity advisory on Oct 6, 2026 (JCSA-20261006-01) warning that the FortiBleed global credential-compromise campaign remains active against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.

The agencies warned that compromised organizations face a problem that patching alone cannot fix. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the agencies wrote, as reported by isec.news. The attack chain has been observed as an initial entry point for ransomware affiliates.

How the campaign works

FortiBleed is not a software vulnerability — it carries no CVE. The campaign relies on reused and leaked credentials combined with legacy SHA-256 password storage, which enables large-scale harvesting and offline cracking using tools such as Hashcat and Hashtopolis run on distributed GPU infrastructure. Once inside, attackers create new administrative accounts and may delete or change existing ones, locking legitimate administrators out of their own devices.

Threat researcher SOCRadar earlier measured the campaign’s scale at more than 86,644 compromised devices across 194 countries in June 2026. That figure is a June measurement, not a current inventory of compromised devices. SOCRadar told The Hacker News it confirmed at least 12 ransomware deployments stemming from FortiBleed-derived access, and federal investigators linked access through the campaign to INC/Lynx and Payload ransomware affiliates, according to eSecurity Planet.

Fortinet's exhibition stall at ITU WTSA 2024 in New Delhi
Fortinet’s exhibition stall at ITU WTSA 2024 in New Delhi. Fortinet says the FortiBleed activity involves reused credentials and brute-force attacks rather than a newly disclosed vulnerability.

Photo: Dev Jadiya, CC BY-SA 4.0, via Wikimedia Commons

Fortinet’s position is that the activity involves reused credentials and brute-force attacks rather than a newly disclosed vulnerability. The campaign first surfaced in June 2026 and, per the Oct 6 advisory, is still running.

What the agencies recommend

The FBI and Secret Service recommend that FortiGate operators:

  • Restrict external management access to the devices
  • Terminate active administrative and VPN sessions
  • Reset credentials across accounts
  • Enforce phishing-resistant multi-factor authentication
  • Review device accounts, configurations, logs, API keys, and password storage settings

What we know

  • The FBI and U.S. Secret Service issued joint advisory JCSA-20261006-01 on Oct 6, 2026, warning the FortiBleed campaign remains active.
  • The campaign targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways using credential abuse — not a software flaw. There is no CVE.
  • Attackers create new admin accounts and may disable or change existing accounts, locking out legitimate administrators.
  • Federal investigators linked FortiBleed-derived access to INC/Lynx and Payload ransomware affiliates; SOCRadar confirmed at least 12 ransomware deployments from such access.
  • Fortinet characterizes the activity as reused credentials and brute-force attacks, not a new vulnerability.

What remains unknown

  • The current count of compromised devices — the 86,644 figure is a June 2026 measurement, not a current inventory.
  • The full roster of ransomware affiliates and victims using FortiBleed-derived access.
  • Whether the campaign’s tempo is growing, stable, or declining since the Oct 6 advisory.

What you can do

  • If you administer FortiGate devices: restrict external management access, terminate active admin and VPN sessions, rotate credentials, and enforce phishing-resistant MFA, per the FBI/Secret Service advisory.
  • Review device accounts, configurations, logs, API keys, and password storage settings for unauthorized changes.
  • Do not assume patching is sufficient — the advisory explicitly warns remediation must go beyond standard patching and password resets.

No corrections have been published for this article.

About the author

Graham Ellis, Staff Writer — beat: consumer security & privacy.