- The FBI and Secret Service say FortiBleed, a credential compromise campaign against Fortinet firewalls and VPN gateways, is ongoing and can lock owners out.
- The agencies say remediation goes beyond standard patching and password resets, and that ransomware affiliates have used the attack chain as a way in.
- Leaders should ask whether device admin pages face the internet, whether admin accounts have been audited, and how the team would regain control if locked out.
A firewall exists to keep outsiders away from a network. FortiBleed, as the FBI and Secret Service describe it, can leave the owner locked out of the firewall itself. The agencies published their alert on Tuesday, as reported by CyberScoop.
What the agencies say is happening
The alert calls FortiBleed a credential compromise campaign. It targets Fortinet firewalls and VPN gateways. The agencies describe it as an ongoing threat.
They warn that attackers can disable accounts or change passwords. Affected organizations "may find themselves locked out of their systems." The fix then needs steps "beyond standard patching and password resets."
The agencies also report a link to ransomware. Investigators have seen the attack chain used as a first foothold by ransomware affiliates. The alert names INC/Lynx and Payload. It says initial access brokers, who sell footholds to other criminals, are supplying that access.
The count has grown, but the numbers are not like for like
SOCRadar's chief information security officer, Ensar Seker, gave CyberScoop a later figure. He said a follow-up investigation found "more than 400,000 or 450,000 firewalls targeted by the wider operation." His wording is a loose estimate, not an exact count.
Handle the two figures with care. One counts devices verified as compromised. The other counts firewalls targeted. Seker said the operation has several parts, so comparing counts over time is imprecise. He still concluded the campaign is "broader and more serious than we understood at the beginning."
Seker also described how the attacks work. He said attackers use stolen credentials to reach exposed Fortinet devices. Once inside, they set up administrator accounts of their own. In some cases, the rightful owners can no longer sign in. That account is his, not a quoted finding of the alert.
Why patching alone is not enough
A patch fixes a flaw in code. A stolen password is not a flaw in code. The alert does not say whether any software vulnerability is involved. It says only that patching alone is not enough.
To the device, a valid login looks like an administrator. This is WebPulse's analysis, not a claim from the alert.
Think of a copied key. A stronger window does not help. You need to learn who holds keys, then change the locks.
The alert's warning fits that logic. If accounts can be disabled or passwords changed, teams need a way to regain control. The sources do not say how the credentials were stolen, so this piece makes no claim about that.
What the agencies recommend
The FBI and Secret Service list six steps for Fortinet customers.
First, limit management access from outside the network, or turn off internet-facing administration entirely. Second, reset credentials. Third, set up multifactor authentication, which asks for a second proof of identity at login.
Fourth, check firewall and VPN user lists for changes nobody approved. Fifth, read logs for lateral movement, meaning attackers hopping to other systems. Sixth, turn on secure credential storage.
The agencies also ask for help. Organizations can share technical clues, such as addresses and account names the attackers used.
Questions to put to your team this week
First, can anyone on the internet reach the admin page of our Fortinet devices? If so, why? Second, when did we last compare the admin account list with the people who should hold those roles?
Third, if an attacker changed our admin passwords tonight, how would we regain control, and who would do it? Fourth, do our logs show new accounts or unusual logins on these devices?
The lesson here is that devices guarding the perimeter need the same identity discipline as any critical system. Patching is one control. Knowing who holds the keys is another, and this alert points to that second control.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CyberScoop.





