🎧 Listen to this article: हिंदी · English · தமிழ் · తెలుగు · ಕನ್ನಡ · മലയാളം · 日本語 · 中文
🌍 Read this in your language: हिंदी · தமிழ் · తెలుగు · ಕನ್ನಡ · മലയാളം · ଓଡ଼ିଆ · 日本語 · 中文
Imagine changing your front-door lock, only to find the burglar had already cut a spare key and quietly removed yours. That is roughly what the latest FortiBleed warning describes for Fortinet firewalls.
Today is October 8, 2026. Two days ago, on October 6, the FBI and the U.S. Secret Service published a joint advisory titled "FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts." It matters right now because the campaign is still active, and because the usual reaction, patch and change the password, can leave the attacker's real foothold in place.
A quick recap: what FortiBleed is
FortiBleed is not a new software bug. Fortinet has said its findings point to credentials reused from earlier incidents, plus brute-force attempts against devices with weak passwords and no multifactor authentication (MFA, a second proof of identity such as a phone prompt).
The attackers target internet-facing FortiGate firewalls and SSL VPN gateways, the boxes that let staff connect to the office network from outside. They use two main techniques:
- Credential stuffing: trying username and password pairs leaked in older breaches.
- Password spraying: trying a few common passwords across many accounts.
Neither needs a fresh exploit. If a device on the internet accepts a password that criminals already have, they simply log in.
What is new in the October advisory: lockouts
The agencies say attackers are now doing more after they get in. They create new administrator accounts on the device. Then they interfere with the real ones, either deleting them or changing their passwords.
The result is ugly. The legitimate team cannot log in to its own firewall, while the intruder keeps control and tries to move deeper into the network. A firewall or VPN gateway is often the heart of remote access, so losing it makes it much harder to inspect settings, remove bad users or cut off connections, at exactly the moment defenders need to.
The advisory is aimed at all 16 U.S. critical infrastructure sectors, including healthcare, energy, financial services, communications and government. It does not give a count of organisations that have been locked out.
How the operation works, step by step
Investigators got an unusual look inside, because the attackers left their own backend server exposed. The open directory showed a full pipeline:
- Find targets. Automated scanners looked for reachable FortiGate SSL VPN login pages.
- Try known credentials. Passwords from earlier Fortinet-related leaks and from infostealer logs (malware that harvests saved passwords from infected computers) were tested.
- Crack stolen hashes. A password hash is a scrambled form of a password. Hashes taken from compromised devices were sent to cracking rigs running Hashcat (password-recovery software) and Hashtopolis (which spreads that work across many machines), sped up with graphics cards.
- Package the access. Scripts checked that logins worked, filtered out suspected honeypots, matched targets to organisations, and ranked victims by revenue and network size.
That last step is the giveaway. This is an initial-access broker operation: people who break in and then sell the way in. The agencies say access from FortiBleed has reached ransomware affiliates, including INC/Lynx and Payload ransomware.
About that big number
The advisory cites research from SOCRadar describing more than 86,644 working device credentials across 194 countries. That is serious, but it is not the same as 86,644 confirmed breaches.
CloudSEK, which also examined the exposed directory, pointed out why. Some company names in the data were linked through contractors, resellers or subsidiaries rather than the company itself, and the raw data also held credentials for non-Fortinet equipment. A working device login is also a different stage from an attacker actually reaching a company's internal Active Directory.
So being listed in an attacker's catalogue tells you to look. It does not tell you how far they got. Only evidence from your own systems can answer that.
Why patching and a password change are not enough
This is the heart of the advisory.
- A patch does not cancel a stolen password. If the password was taken earlier, it still works after the update.
- A password reset does not remove an account the attacker created. Their own admin account stays.
- API keys survive user password resets. FortiGate devices can be managed through REST API keys, used for automation, backups and monitoring. An unknown key is a back door that a normal reset will not touch.
There is also a subtle storage detail. Fortinet introduced stronger password storage using PBKDF2 (a method that makes stored passwords much slower to crack) in FortiOS 7.2.11, 7.4.8 and 7.6.1. After upgrading from an older release, an existing admin's password stays in the older SHA-256 form until that admin logs in or the password is changed. Older hashes can also linger in a hidden compatibility setting even after conversion. Fortinet documents how to remove them, and the exact setting depends on the firmware version.
Those version numbers mark when the feature arrived, not which release to run. And stronger storage cannot take back a password an attacker already cracked.
Checking and recovering: a practical sequence
If you run internet-facing Fortinet gateways, here is a plain version of the advisory's guidance.
Step 1: Look before you wipe
Collect evidence first. Compare the device configuration with a known-good copy to spot added users and changed settings. Review firewall and VPN logs, and also domain controller and authentication logs, to see whether activity reached the internal network. The advisory's indicator table covers activity between June 18 and July 23, 2026, which gives you windows to search in retained logs.
Step 2: Review every admin account and API key
Check each account's owner, creation date and privileges against your records. The advisory lists account names seen in investigations, such as adminin, forticloud-tech, forticloud-sync, support_fortinet, system_config and adminsslvpn. Treat these as leads, not verdicts. A support-sounding name does not make an account legitimate, and a name match alone does not prove it is malicious. Remove unknown API keys and refresh the legitimate ones.
Step 3: Cut existing access, then reset
End active admin and VPN sessions, so anyone already logged in is thrown out. Reset the related passwords. If the device is connected to Active Directory or LDAP, Fortinet advises treating that integration account as compromised and watching for its use elsewhere.
Step 4: Lock down management access
Require phishing-resistant MFA for remote access and administration. Limit who can reach the management interface using trusted hosts or local-in policies. The strongest option is not exposing administration to the internet at all.
Step 5: Hunt, plan the eviction, and report
Isolate affected hosts and hunt for movement inside the network before declaring victory. Getting back into the firewall is not proof the rest of the environment is clean. The agencies ask victims to report through the FBI's Internet Crime Complaint Center or a local FBI or Secret Service field office, and they discourage paying ransoms, since payment does not guarantee recovery.
A note on indicators: the advisory warns that listed IP addresses may belong to cloud infrastructure that has since been reassigned. Match them against the right time period and other evidence before blocking or accusing anyone.
Conclusion
FortiBleed has moved from stealing passwords to taking over the devices and keeping them. The October 6 advisory makes one point very clearly: an update and a new password close the door you know about, not the ones the attacker added. Check accounts, keys and logs, cut existing sessions, and lock down who can manage the device. For leaders, the question is no longer "is the firewall patched?" but "can we prove nobody else is holding the keys?"
Merits
- Following the advisory removes attacker footholds that patching alone misses.
- MFA and restricted management access block the most common way in, reused passwords.
- Configuration and API key reviews catch quiet back doors early.
- Searching logs for the published time windows can reveal past intrusions you did not know about.
- Reporting incidents helps the agencies track and disrupt the operation.
Demerits
- A proper investigation takes time and skilled people, which smaller teams may lack.
- Removing internet-facing administration can make remote management less convenient.
- Removing legacy hash compatibility can cause problems if a device is later moved to older firmware.
- Indicator lists age quickly, and IP addresses can be reassigned, so they need careful handling.
- Ending all sessions and resetting passwords disrupts users while it happens.
Caution
This article is for educational purposes and summarises a public advisory in plain language. It is not a substitute for the official FBI and Secret Service advisory or Fortinet's own guidance, which should be read in full before acting. Any names, settings or examples here must be checked against your own environment and current vendor documentation. If you suspect a compromise, involve qualified incident responders and follow your organisation's procedures.
Frequently asked questions
- What is FortiBleed? — It is a credential-based campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, using leaked, reused and cracked passwords rather than a new software flaw.
- Is FortiBleed a new Fortinet vulnerability? — No. Fortinet says the activity reflects reused credentials and brute-force attempts against devices with weak passwords and no MFA.
- What did the October 6, 2026 advisory add? — It warns that attackers create their own admin accounts and delete or change real ones, locking legitimate administrators out of their devices.
- Will updating FortiOS stop the attack? — Updating helps, but it does not cancel a stolen password, remove an attacker-created account or revoke an unknown API key, so those need separate review.
- What is PBKDF2 and why does it matter here? — It is a stronger way to store passwords that makes cracking slower; after an upgrade, older admin hashes can remain until passwords are changed or legacy hashes are removed.
- Does 86,644 mean 86,644 companies were breached? — No. It refers to working device credentials found by researchers, which is different from confirmed intrusions into company networks.
- Which ransomware groups are linked to FortiBleed? — The agencies say access from the campaign has reached affiliates of INC/Lynx and Payload ransomware.
- Where should victims report a FortiBleed incident? — In the U.S., through the FBI's Internet Crime Complaint Center or a local FBI or Secret Service field office.
Tags
#FortiBleed #Fortinet #FortiGate #CyberSecurity #IncidentResponse #Ransomware #CredentialStuffing #MFA #NetworkSecurity #FBI
Docker Security Checklist
Lock down your containers from build to runtime — 29 practical controls covering images, runtime flags, secrets, and the daemon. Enter your email — you'll get the PDF instantly, plus new posts on Docker, Linux & security.
Free. No spam — unsubscribe in one click.


Responses
Sign in to leave a response.