The FBI has issued a fresh warning that the FortiBleed attack campaign is still active, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators.
According to the bureau, hackers gain access to exposed endpoints using previously leaked credentials, or logins obtained from infostealer logs, credential stuffing and password spraying attacks. They then extract additional authentication data from compromised devices and use a distributed GPU cluster running Hashcat and Hashtopolis to crack the stolen password hashes offline.
"The FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates," the FBI said, naming INC/Lynx ransomware and Payload ransomware among groups benefiting from the campaign.
FortiBleed stems from a massive Fortinet credentials leak discovered in June, when attackers inadvertently exposed a server containing usernames and plaintext passwords associated with 73,932 firewall URLs across 194 countries. The data revealed a large-scale credential-harvesting operation, though the method used to obtain the configuration data was unclear at the time.
In July, security firm SOCRadar linked FortiBleed to the INC and Lynx ransomware operations after gaining access to both groups' negotiation panels on a server used in the campaign. SOCRadar's latest count puts the number of compromised devices at 86,644.
The FBI said that in some incidents, the threat actor creates administrator accounts and uses their privileges to delete existing admin accounts or change their passwords, denying victims access to their devices. The attacker then establishes persistence and attempts to move laterally within the environment.
Details of the operation emerged after the attacker accidentally exposed their backend server, revealing a directory containing tooling and datasets. This showed automated scripts scanning exposed FortiGate SSL VPN portals, the distributed GPU password-cracking setup, and scripts to validate credentials, filter out honeypots, identify organisations and prioritise targets by revenue and network structure.
The exposure also revealed working VPN configurations and target lists, indicating the operator was packaging compromised access for sale.
The FBI warned that remediation may require more than patching and resetting Fortinet passwords, suggesting organisations restrict external access, terminate all active VPN sessions, enforce multi-factor authentication and review logs for unauthorised changes and suspicious activity. It also recommended enforcing PBKDF2 for administrator password storage, which is much stronger than legacy SHA-256 hashes that attackers can practically crack offline.