NEWS

Alert: FortiBleed Remains an Active Campaign, Can Lock Out Users or Lead to Ransomware

The FBI and Secret Service warn FortiBleed is still active, now tied to 400,000+ Fortinet devices and causing lockouts that precede ransomware attacks.

Dylan H.

News Desk

October 6, 2026
7 min read
Alert: FortiBleed Remains an Active Campaign, Can Lock Out Users or Lead to Ransomware

FBI, Secret Service Confirm FortiBleed Is Still Active Months Later

The FBI and the U.S. Secret Service issued a joint cybersecurity advisory on Tuesday, October 6, 2026, warning that FortiBleed — the Fortinet credential-harvesting campaign first disclosed in June 2026 — remains an active, ongoing global threat. The federal warning significantly raises the campaign's known scale: where earlier reporting tracked roughly 73,932 to 86,644 exposed FortiGate portals across 194 countries, the FBI and Secret Service now say the wider operation has targeted more than 400,000 Fortinet devices. Officials cautioned that compromised organizations may find themselves locked out of their own systems as attackers disable accounts or change passwords, and that FortiBleed access continues to feed directly into ransomware attacks.


Advisory Details

AttributeValue
AdvisoryJoint FBI / U.S. Secret Service cybersecurity advisory
PublishedTuesday, October 6, 2026
Campaign NameFortiBleed
First DisclosedJune 2026 (SOCRadar, following researcher Volodymyr Diachenko's discovery of an exposed dataset)
TargetInternet-facing Fortinet FortiGate firewalls and SSL VPN gateways
Scale (initial findings)~86,644 compromised devices across 194 countries
Scale (per FBI/Secret Service)400,000–450,000+ Fortinet devices targeted in the wider operation
Root CauseCredential reuse/leaked passwords combined with legacy SHA-256 password storage on FortiOS builds older than 7.6.1, 7.4.8, or 7.2.11
Primary ImpactAccount lockouts, unauthorized admin account creation, downstream ransomware
Ransomware TiesINC Ransom and Lynx affiliates
Vulnerability TypeNot a new CVE — credential compromise and weak legacy password hashing

What's New in This Warning

A Campaign That Never Went Away

CosmicBytez Labs has tracked FortiBleed since it first surfaced in June 2026, when a leaked dataset of Fortinet VPN credentials for roughly 73,932 devices began circulating. Follow-on research from SOCRadar found the operation used a custom Golang-based packet sniffer — internally referred to as FortigateSniffer — that abuses a native FortiOS diagnostic command to passively capture authentication traffic across two dozen protocols, harvesting both cleartext and hashed credentials. By early July 2026, SOCRadar had tied the infrastructure to INC Ransom and Lynx ransomware negotiation panels, confirming at least 12 ransomware deployments traced back to FortiBleed access.

Tuesday's advisory is the first time the FBI and Secret Service have formally confirmed, four months on, that the campaign is still running — and that its reach is far larger than initially understood.

The Scale Jump, Explained

The jump from roughly 86,644 devices to 400,000–450,000+ reflects differing snapshots rather than a single new wave of attacks. According to SOCRadar CISO Ensar Seker, the original figures covered devices confirmed compromised in an exposed staging server discovered mid-year; the broader federal tally reflects the full scope of the wider operation — every FortiGate portal scanned, probed, or targeted since the campaign began. As Seker put it, the updated numbers "show the campaign is broader and more serious than we understood at the beginning."

How the Lockouts Happen

The advisory stresses that FortiBleed does not rely on a software flaw. Attackers use credentials obtained through reuse, prior leaks, or cracked legacy SHA-256 password hashes to log into FortiGate admin and SSL VPN portals directly. Once inside, they disable legitimate accounts or change their passwords, and in some cases create unauthorized administrative accounts to maintain persistence. That combination is why the FBI and Secret Service say remediation requires "steps beyond standard patching and password resets" — a defender who simply resets a known-compromised password may still find the attacker has a second, hidden admin account waiting in reserve.

The Ransomware Pipeline

The advisory reiterates what CosmicBytez Labs reported in July: FortiBleed functions as an initial-access broker operation, with harvested FortiGate access sold or handed off to ransomware affiliates. INC Ransom and Lynx remain the two groups explicitly named as having used FortiBleed-derived access to stage ransomware deployments. The durability of that link — confirmed independently by federal law enforcement months after SOCRadar's initial reporting — indicates this is a sustained criminal supply chain, not a one-off wave.


Impact Assessment

Impact AreaDescription
AvailabilityLegitimate administrators and VPN users can be locked out of firewall and VPN management interfaces
PersistenceRogue admin accounts created by attackers can survive routine password resets and basic remediation
ConfidentialityHarvested VPN and admin credentials enable follow-on access to internal networks
Ransomware RiskConfirmed initial-access pipeline feeding INC Ransom and Lynx affiliates
Remediation ComplexityStandard patch-and-reset response is explicitly called insufficient by federal advisory
Scope400,000+ Fortinet devices across 194+ countries potentially implicated in the wider operation

Recommendations

For Fortinet Administrators

  • Terminate all active administrative and SSL VPN sessions immediately, not just those tied to accounts you suspect are compromised.
  • Reset all credentials — admin and VPN — rather than rotating only flagged accounts; attacker-created accounts may not be flagged at all.
  • Upgrade to FortiOS 7.6.1, 7.4.8, 7.2.11, or later to move credential storage off legacy SHA-256 hashing and onto PBKDF2.
  • Audit for unauthorized administrative accounts created without IT's knowledge or approval.
  • Restrict management interfaces to trusted hosts and disable internet-facing admin portals wherever feasible.

For Security Teams

  • Enforce phishing-resistant MFA on all VPN and administrative access paths — the advisory names this explicitly as a required mitigation, not an optional hardening step.
  • Review authentication and configuration logs for signs of lateral movement, unexpected use of diagnostic commands, or unusual outbound traffic consistent with the FortigateSniffer implant.
  • Hunt for INC Ransom and Lynx TTPs in any environment with internet-exposed FortiGate infrastructure.
  • Treat internet-facing FortiGate exposure as an active incident-response scenario, not a routine patch cycle — assume compromise until proven otherwise.

For Affected Organizations and Users

  • Verify lockout or password-reset notices through official IT channels before acting on them; attackers' own account changes can be mistaken for legitimate security prompts, and vice versa.
  • Report unexpected authentication failures or password-reset emails immediately rather than assuming routine IT maintenance.
  • Expect multi-day remediation timelines if an administrative account compromise is confirmed — full recovery involves more than a single password change.

Key Takeaways

  1. The FBI and Secret Service confirmed on October 6, 2026, that FortiBleed remains an active campaign, four months after it was first disclosed.
  2. The known scale has grown from roughly 86,644 devices to more than 400,000–450,000 Fortinet devices targeted in the wider operation, per SOCRadar's Ensar Seker.
  3. The campaign exploits credential reuse and legacy SHA-256 password hashing on older FortiOS builds — it is not driven by a new CVE.
  4. Attackers lock out legitimate users by disabling accounts, changing passwords, and creating unauthorized admin accounts for persistence.
  5. FortiBleed continues to feed ransomware operations, with INC Ransom and Lynx affiliates confirmed using the stolen access.
  6. Federal guidance says standard patching and password resets are not enough — organizations need session termination, full credential resets, MFA, and account audits.

Sources