The FBI and Secret Service have issued a joint alert regarding "FortiBleed," a credential compromise campaign targeting Fortinet firewalls and VPN gateways. The agencies confirm that the campaign remains active and poses a significant threat, potentially leading to user lockouts and serving as an initial entry point for ransomware attacks.
According to the alert, threat actors leveraging FortiBleed can disable legitimate user accounts or change passwords, effectively locking organizations out of their Fortinet systems. Such actions necessitate remediation steps beyond simple patching and password resets. The attack chain has also been observed providing initial access for ransomware affiliates, including groups identified as INC/Lynx and Payload.
The FortiBleed campaign was initially uncovered earlier this year. At that time, SOCRadar verified over 86,644 compromised devices across 194 countries. Subsequent investigations by SOCRadar revealed a broader scope, identifying between 400,000 and 450,000 firewalls targeted by the operation. This indicates the campaign is more extensive and serious than initially understood.
The FBI and Secret Service emphasize that attackers are actively using stolen credentials to access exposed Fortinet devices, create new administrative accounts, and in some instances, completely lock out legitimate owners. The government warning corroborates the most concerning aspects of the FortiBleed threat, including its ongoing nature and its potential to lead to ransomware.
To mitigate the risk, the FBI and Secret Service recommend several measures for Fortinet customers. These include restricting external management access or entirely removing internet administration capabilities, resetting all credentials, implementing multifactor authentication, and reviewing firewall and VPN user configurations for any unauthorized changes. Organizations should also review logs for signs of potential lateral movement and ensure secure credential storage is enabled.
The agencies are actively seeking information and indicators of compromise from affected organizations. This includes any observed IP addresses used by attackers and any usernames associated with malicious activity.






