FortiBleed: FBI says 86,644 Fortinet device credentials still in play
FortiGate SSL VPN credential harvesting and admin lockout

FortiBleed: FBI says 86,644 Fortinet device credentials still in play

The FBI and U.S. Secret Service warned on 6 October 2026 that FortiBleed is still an active threat against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The campaign is estimated to hold more than 86,644 working device credentials across 194 countries, counted as of 19 June 2026. Operators keep scanning with credentials they already have.

What happened

FortiBleed is a credential-harvesting and initial-access operation, not a single software bug. Attackers find exposed VPN portals, then use credential stuffing and password spraying built from old leak dumps and infostealer logs. Legacy SHA-256 password storage on some appliances makes stolen hashes easier to crack offline.

After access, a Go tool called FortigateSniffer passively intercepts authentication traffic. Cracked passwords are validated, sorted, and sold. Overlap has been reported with INC and Lynx ransomware affiliates. Victims can be locked out when attackers create new admin accounts and delete or reset the originals.

Who is affected

Any organisation with an internet-facing FortiGate or Fortinet SSL VPN, especially where admin or VPN passwords were reused, leaked, or stored with the older hash. Managed service providers that share a password pattern across customer firewalls are a high-value target.

  • Suspicious account names seen in the advisory include adminin, fortiAdmin, forticloud-sync, support_fortinet, system_config, and forti_support2
  • Do not treat a username match alone as proof; verify every local admin against a known-good config
  • Access from this campaign has been linked onward to ransomware affiliates

What to do now

Inventory internet-facing FortiGates, terminate admin and SSL VPN sessions, reset those passwords, and turn on phishing-resistant MFA. Move credential storage to PBKDF2, remove unknown local admins and REST API keys, and restrict management to trusted hosts. If you suspect lockout, isolate the device, pull logs, and do not assume a password reset alone evicts the attacker.

Source: The Hacker News, 7 October 2026, FBI warns FortiBleed remains active after 86,644 Fortinet device credentials. Joint advisory: IC3 CSA 261006.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-21589: unauthenticated file read on Atlassian Data Center
Jira Confluence Bitbucket arbitrary file access CVSS 9.3