Skip to content
Security & Trust

FBI: FortiBleed still targets Fortinet firewalls using leaked logins

The agencies point to reused or leaked passwords and fast legacy password storage as what the campaign relies on.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
FBI: FortiBleed still targets Fortinet firewalls using leaked logins
In brief
  • The FBI and Secret Service say FortiBleed remains active against internet-facing Fortinet firewalls, citing reused or leaked credentials. One reported estimate counts more than 86,644 working credentials as of June 19.
  • Attackers record sign-in traffic, crack the hashes offline and may sell the access. The agencies suspect links to INC and Lynx ransomware.
  • Review firewall admin accounts, reset VPN and admin passwords, require phishing-resistant sign-in and check logs. Report suspected compromise to the FBI and USSS.

A password does not expire when the breach that exposed it fades from memory. The FBI and U.S. Secret Service say the FortiBleed campaign works because of reused or leaked credentials. On Tuesday they said it is still active. Its targets are internet-facing Fortinet FortiGate firewalls and their SSL VPN gateways. An SSL VPN lets staff reach the company network from outside.

The lesson here is plain. A firewall protects a network only while its own logins stay private. This campaign gathers those logins from the device itself. The question for leaders is who still holds working credentials.

What the agencies reported

The Hacker News reported the warning on October 7. It says FortiBleed was first documented in June 2026. It calls the operation Russian-speaking. The agencies say attackers keep scanning exposed Fortinet firewalls. They try logins obtained earlier.

The agencies name two weaknesses: reused or leaked credentials, and older SHA-256 password storage. In their words, this lets attackers collect and crack login data "at scale."

86,644+
Working Fortinet device credentials, estimated
Source: The Hacker News reporting on the FBI and USSS warning (October 7, 2026); estimate as of June 19, 2026
194
Countries the credentials span
Source: The Hacker News (October 7, 2026); estimate as of June 19, 2026

The Hacker News does not say who produced the estimate. Treat it as a reported figure, not an audited count.

How the attack works

The Hacker News describes five stages. Each builds on the one before.

First, attackers scan the internet for exposed login portals. Second, they replay logins from earlier leaks and from infostealer logs. Infostealers are malware that copy saved logins from infected computers.

Two methods are used. Credential stuffing replays known username and password pairs. Password spraying tries a few common passwords across many accounts.

Third, attackers place a Go-based tool called FortigateSniffer on the firewall. It passively watches sign-in traffic across 24 protocols. It records credentials and password hashes. A hash is a scrambled form of a password.

24
Protocols FortigateSniffer watches for sign-ins
Source: The Hacker News reporting on the FBI and USSS warning (October 7, 2026)

Fourth, the hashes go to a cracking cluster built on graphics processors. It runs Hashmat and Hashtopolis. The cracking happens offline. The firewall never sees the guesses, so it cannot block them.

Fifth, the recovered logins are used inside the network. Attackers list accounts in Active Directory, the company's central user directory. They test logins against internal systems, including file shares. They copy data from network shares. Session cookies keep them signed in.

Why the hash type matters

A hash is meant to make a captured password list hard to use. SHA-256 is built to be fast. That speed helps whoever is guessing. Cracking hardware can test a very large number of guesses quickly.

CISA advised Fortinet customers to store administrator credentials with PBKDF2. That method is designed to be slow. CISA also listed other steps:

Use phishing-resistant authentication. End active SSL VPN and admin sessions. Reset VPN and admin passwords. Review logs for unusual activity.

Access that may be resold

The agencies suspect the operator is an initial access broker. That is a seller of network footholds to other criminals. They cite overlaps with INC and Lynx ransomware operations. These likely point to access being used for ransomware.

The agencies also described how the operators sort what they collect. Scripts filter out honeypots, which are decoy systems. They map organisations and rank targets by revenue and network structure.

The agencies also describe changes to the firewall itself. Attackers create new administrator accounts. In some cases they delete existing ones. That can leave the owner unable to sign in to the device.

Questions for your security team

Ask whether the company runs FortiGate firewalls or SSL VPN gateways. Ask who owns them. Ask whether VPN and admin passwords have been reset since June. Ask whether phishing-resistant sign-in covers every VPN login.

Ask for a current list of administrator accounts on each firewall. Any account nobody can explain needs review. So does any account that has disappeared. Ask where logs from these devices are stored.

Ask what happens if the team cannot sign in. The agencies advise isolating affected devices and collecting logs and artifacts. They also advise reporting to the FBI and USSS. Settle the backup route to the device before it is needed.

A firewall is only as private as its own logins. An old password from an earlier leak is easy to forget. This campaign is built to find it.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Hacker News.

Share this insight