FBI warns FortiBleed attacks still active as hackers lock out FortiGate VPN admins

Credential leak linked to ransomware affiliates continues to hit exposed Fortinet firewalls

By LineZotpaper
Published
Read Time3 min
The FBI is warning that FortiBleed attacks are ongoing, with hackers using leaked credentials to break into exposed Fortinet FortiGate firewalls and SSL VPN gateways, stealing data and locking out legitimate administrators.

The FBI has issued a fresh warning that the FortiBleed attack campaign is still active, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators.

According to the bureau, hackers gain access to exposed endpoints using previously leaked credentials, or logins obtained from infostealer logs, credential stuffing and password spraying attacks. They then extract additional authentication data from compromised devices and use a distributed GPU cluster running Hashcat and Hashtopolis to crack the stolen password hashes offline.

"The FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates," the FBI said, naming INC/Lynx ransomware and Payload ransomware among groups benefiting from the campaign.

FortiBleed stems from a massive Fortinet credentials leak discovered in June, when attackers inadvertently exposed a server containing usernames and plaintext passwords associated with 73,932 firewall URLs across 194 countries. The data revealed a large-scale credential-harvesting operation, though the method used to obtain the configuration data was unclear at the time.

In July, security firm SOCRadar linked FortiBleed to the INC and Lynx ransomware operations after gaining access to both groups' negotiation panels on a server used in the campaign. SOCRadar's latest count puts the number of compromised devices at 86,644.

The FBI said that in some incidents, the threat actor creates administrator accounts and uses their privileges to delete existing admin accounts or change their passwords, denying victims access to their devices. The attacker then establishes persistence and attempts to move laterally within the environment.

Details of the operation emerged after the attacker accidentally exposed their backend server, revealing a directory containing tooling and datasets. This showed automated scripts scanning exposed FortiGate SSL VPN portals, the distributed GPU password-cracking setup, and scripts to validate credentials, filter out honeypots, identify organisations and prioritise targets by revenue and network structure.

The exposure also revealed working VPN configurations and target lists, indicating the operator was packaging compromised access for sale.

The FBI warned that remediation may require more than patching and resetting Fortinet passwords, suggesting organisations restrict external access, terminate all active VPN sessions, enforce multi-factor authentication and review logs for unauthorised changes and suspicious activity. It also recommended enforcing PBKDF2 for administrator password storage, which is much stronger than legacy SHA-256 hashes that attackers can practically crack offline.

§

Analysis

Why This Matters

  • The campaign has moved beyond credential theft: attackers are locking legitimate administrators out of their own firewalls, which can cripple network access and speed up ransomware deployment.
  • With over 86,000 devices compromised, the leak continues to fuel a steady stream of intrusions even months after it was first disclosed.
  • The FBI explicitly links FortiBleed to ransomware affiliates, meaning victims face both network compromise and extortion demands.

Background

FortiBleed refers to a large-scale credential leak disclosed in June, in which an attacker's own server was inadvertently exposed, revealing usernames and plaintext passwords tied to tens of thousands of FortiGate firewall URLs across nearly 200 countries. Investigators later tied the operation to known ransomware groups. The campaign relies on exposed VPN endpoints and weak or stolen credentials, cracking password hashes offline with powerful GPU clusters before using them to gain entry.

Key Perspectives

Fortinet customers and administrators: Face a heightened risk of lockout and lateral movement. The FBI stresses that patching and password resets alone may be insufficient given how much data the attacker has already harvested. Ransomware groups (INC/Lynx and Payload): Treat FortiBleed as a reliable initial access vector, according to the bureau, packaging compromised access for sale and escalating to extortion. Security researchers (SOCRadar): Have tracked the scope of the compromise, linking it to specific ransomware operations and revising the count of affected devices upward as more evidence emerges.

What to Watch

  • Whether Fortinet releases patches or guidance specifically addressing the lockout vectors described by the FBI.
  • Any further revisions to the compromised device count or new links to additional ransomware groups.
  • Organisations' compliance with the FBI's remediation guidance, particularly the move to PBKDF2 password hashing and enforced MFA.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.