FBI and Secret Service confirm ongoing attacks using FortiBleed credentials

Criminals lock organisations out of Fortinet firewalls, with more than 86,000 devices compromised globally

By LineZotpaper
Published
Read Time2 min
The FBI and US Secret Service have issued a joint advisory warning that attackers involved in the FortiBleed campaign are locking organisations out of their Fortinet firewalls, with evidence linking the stolen credentials to ransomware attacks by the INC/Lynx and Payload groups.

The FBI and US Secret Service say criminals using credentials linked to the FortiBleed campaign are locking organisations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries.

"Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," the advisory states. "During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment."

The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways. Criminals use credentials from earlier breaches and infostealer logs for credential stuffing and password spraying, then extract password hashes from compromised devices and crack them offline using GPU-accelerated clusters.

The agencies urged organisations to restrict internet-facing management access, terminate active administrative and VPN sessions, reset passwords, and enable phishing-resistant multi-factor authentication. The advisory also links FortiBleed to ransomware campaigns, saying initial access brokers supplied compromised-network access to ransomware affiliates.

The current evidence points to affiliates working for the INC/Lynx and Payload ransomware groups making use of the credentials. SOCRadar said in July that it had seen at least 12 confirmed ransomware attacks stemming from FortiBleed.

The agencies encouraged victims to report incidents, while noting that organisations were not obliged to provide information in response to this advisory. The FBI and the Secret Service said victim reports could help identify indicators of compromise and warned against paying ransoms.

§

Analysis

Why This Matters

  • The scale of the compromise is vast, with over 86,000 devices in 194 countries potentially exposed, meaning organisations worldwide may face lockouts and ransomware attacks.
  • The attacks demonstrate a sophisticated, multi-stage approach where criminals use credential stuffing, offline hash cracking, and lateral movement, making them difficult to defend against without proactive measures.
  • The connection to ransomware groups INC/Lynx and Payload raises the stakes, as initial access brokers are selling compromised network access to ransomware affiliates, increasing the likelihood of extortion.

Background

FortiBleed refers to a campaign targeting Fortinet firewalls and SSL VPN gateways, first identified by security researchers. The attackers rely on credentials stolen from earlier breaches, including infostealer logs, to break into devices. Once inside, they extract password hashes and crack them offline. The current advisory from the FBI and US Secret Service builds on earlier reporting by The Register and SOCRadar about the campaign's connection to ransomware operations.

Key Perspectives

Law enforcement (FBI and US Secret Service): The agencies seek to warn victim organisations about the specific tactics being used, encourage reporting to improve threat intelligence, and explicitly discourage ransom payments.

Victim organisations: Many may be unaware their Fortinet devices are compromised until they are locked out. They face disruptive operational impacts and pressure to respond without clear guidance on recovery timelines.

Critics and security observers: Some may question why the advisory comes months after the initial reporting by SOCRadar and The Register. The lack of mandatory reporting and the difficulty of implementing countermeasures for organisations with limited IT resources remain concerns.

What to Watch

  • Whether additional ransomware groups begin using FortiBleed credentials, expanding the threat beyond INC/Lynx and Payload affiliates.
  • The rate at which organisations implement the recommended mitigations, such as restricting internet-facing management access and enabling phishing-resistant MFA.
  • Potential follow-up advisories or technical guidance from Fortinet itself regarding affected device models or firmware updates.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.