The FBI and US Secret Service say criminals using credentials linked to the FortiBleed campaign are locking organisations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries.
"Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," the advisory states. "During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment."
The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways. Criminals use credentials from earlier breaches and infostealer logs for credential stuffing and password spraying, then extract password hashes from compromised devices and crack them offline using GPU-accelerated clusters.
The agencies urged organisations to restrict internet-facing management access, terminate active administrative and VPN sessions, reset passwords, and enable phishing-resistant multi-factor authentication. The advisory also links FortiBleed to ransomware campaigns, saying initial access brokers supplied compromised-network access to ransomware affiliates.
The current evidence points to affiliates working for the INC/Lynx and Payload ransomware groups making use of the credentials. SOCRadar said in July that it had seen at least 12 confirmed ransomware attacks stemming from FortiBleed.
The agencies encouraged victims to report incidents, while noting that organisations were not obliged to provide information in response to this advisory. The FBI and the Secret Service said victim reports could help identify indicators of compromise and warned against paying ransoms.