The FBI is warning that FortiBleed attacks are still active. Exposed Fortinet FortiGate firewalls and SSL VPN gateways are being taken over with previously leaked credentials, infostealer logs, credential stuffing, and password spraying. In some cases the attacker then deletes admin accounts or changes their passwords, locking the real administrators out.
What happened
FortiBleed surfaced in June 2026, when a backend server exposed usernames and plaintext passwords tied to 73,932 firewall URLs across 194 countries. SOCRadar's latest count is about 86,644 confirmed-compromised devices, not a mere exposure estimate. Devices breached months ago remain in the actor's inventory.
Attackers pull password hashes from compromised appliances and crack them offline on a GPU cluster. The FBI says the chain has been used as initial access for INC/Lynx and Payload ransomware affiliates. A joint FBI and US Secret Service notice this week says remediation can require more than a password reset.
Who is affected
- Internet-facing FortiGate firewalls and SSL VPN gateways, especially any appliance whose credentials appeared in the June leak
- Organisations that reset a password but left management or VPN sessions alive
- Sites still storing administrator passwords with legacy hashes instead of PBKDF2
What to do now
Treat a previously exposed FortiGate as compromised until you prove otherwise. Restrict internet-facing management, terminate every admin and VPN session, reset credentials, and turn on phishing-resistant MFA. Review firewall, VPN, authentication, and domain-controller logs for new accounts and lateral movement. Enforce PBKDF2 for administrator password storage.
Source: BleepingComputer, FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- tensorlake 0.5.144 npm worm steals cloud and AI-tool secrets
- CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
- .gh .sl .as registry hijacks minted 12 Google certificates
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.