A fully patched FortiGate can still be someone else's firewall. The FBI and U.S. Secret Service say the FortiBleed credential campaign is still logging into exposed devices and, in some cases, locking the real admins out.
What happened
On 6 October 2026 the agencies published joint advisory JCSA-20261006-01. They cite SOCRadar's count of more than 86,644 compromised FortiGate firewalls and SSL VPN gateways across 194 countries. Attackers scan for internet-facing portals, stuff and spray credentials from earlier leaks and infostealer logs, pull user databases and session material, and crack hashes offline.
Once in, they create new admin accounts. Some victims then find original accounts disabled or passwords changed. The advisory also ties the access to ransomware affiliates of INC/Lynx and Payload. This is not a new firmware bug. There is no patch for a stolen password.
Who is affected
Any organisation with an internet-facing FortiGate firewall or FortiGate SSL VPN, including sites that already installed current FortiOS. Reused local passwords and exposed management interfaces are the exposure, not an unpatched CVE.
- Internet-facing SSL VPN and admin portals are the entry point.
- Lockout is possible if the attacker changes or deletes the original admin.
- Stolen access is being offered to ransomware affiliates, so a quiet login is not a harmless login.
What to do now
Take management off the internet, terminate admin and VPN sessions, reset local credentials, and turn on phishing-resistant MFA. Review every firewall and VPN user for accounts you did not create. Hunt authentication logs for stuffing and for new admins. If you are already locked out, treat it as a compromise, not a forgotten password.
Source: The Record, FBI, Secret Service add to warnings of FortiBleed credential stealing campaign. Advisory PDF: JCSA-20261006-01.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- CVE-2026-105192: LMCache CVSS 9.8 RCE still unpatched
- ASOS breach: stolen employee login exposed customer contacts
- ARTEX: AI pentest tool used to steal South Korean bank data
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.