News · Defence & Security
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
FortiBleed is an ongoing attack campaign involving exposed Fortinet credentials and devices. Attackers use those credentials to enter FortiGate firewalls and SSL VPN gateways. The campaign matters because these systems control access into organizations and can provide a powerful starting point for further compromise. The operation became visible after attackers accidentally exposed a backend server. The server contained usernames and plaintext passwords associated with 73,932 firewall URLs. Investigators also found scripts that scanned exposed FortiGate SSL VPN portals, validated credentials, and extracted additional authentication data from compromised devices. The FBI says FortiBleed attacks are still active. Some incidents involve attackers creating administrator accounts, deleting existing admins, or changing their passwords. The campaign has also been observed as an initial entry point for ransomware affiliates, including INC/Lynx ransomware and Payload ransomware.
Based on reporting by Bleeping Computer
What is FortiBleed, and which Fortinet systems does it target?
FortiBleed is an ongoing attack campaign involving exposed Fortinet credentials and devices. Attackers use those credentials to enter FortiGate firewalls and SSL VPN gateways. The campaign matters because these systems control access into organizations and can provide a powerful starting point for further compromise.
The operation became visible after attackers accidentally exposed a backend server. The server contained usernames and plaintext passwords associated with 73,932 firewall URLs. Investigators also found scripts that scanned exposed FortiGate SSL VPN portals, validated credentials, and extracted additional authentication data from compromised devices.
The FBI says FortiBleed attacks are still active. Some incidents involve attackers creating administrator accounts, deleting existing admins, or changing their passwords. The campaign has also been observed as an initial entry point for ransomware affiliates, including INC/Lynx ransomware and Payload ransomware.
How are attackers using exposed FortiGate SSL VPN portals and stolen credentials to gain access?
Attackers begin by locating exposed FortiGate SSL VPN portals and trying credentials already available to them. These may come from earlier leaks, infostealer logs, credential stuffing, or password spraying. This approach lets them exploit reused or weak credentials without needing to discover every password from scratch.
After entering a device, attackers extract additional authentication data, including password hashes. They use a distributed GPU cluster running Hashcat and Hashtopolis to crack those hashes offline. Scripts validate the results, filter out honeypots, identify organizations, and rank targets by revenue and network structure.
The exposed backend server showed how automated the process had become. It contained scanning tools, working VPN configurations, and target lists. The operator was also packaging compromised access for sale, turning stolen credentials and VPN entry points into a broader access-brokering operation.
How widespread is the campaign, in terms of compromised devices, firewall URLs, and countries affected?
FortiBleed has spread across a very large number of exposed Fortinet systems. SOCRadar’s latest count identified 86,644 compromised devices. The original credential leak contained usernames and plaintext passwords associated with 73,932 firewall URLs, showing that the campaign’s reach extended across many separate endpoints.
The leaked firewall data covered 194 countries. Attackers used automated scripts to scan exposed FortiGate SSL VPN portals and organize the results. They also identified organizations and prioritized targets according to revenue and network structure, suggesting deliberate selection rather than random access attempts.
These figures describe different parts of the operation. The 73,932 figure counts firewall URLs linked to leaked credentials, while 86,644 counts compromised devices in SOCRadar’s latest tally. Together, they show a broad campaign affecting organizations worldwide and creating many possible paths into networks.
What can attackers do after gaining administrator privileges, and why does locking out legitimate admins create a serious security risk?
Administrator access gives attackers control over important Fortinet device settings and user accounts. According to the FBI, they can create administrator accounts, delete existing administrator accounts, or change their passwords. These actions can immediately prevent legitimate administrators from managing or securing the affected device.
For example, an attacker may enter with a compromised account, create another privileged account, and then remove the original administrators. The attacker can also change passwords so authorized staff lose access. This is possible because the attacker is operating with administrator privileges on the firewall or VPN gateway.
The lockout creates a serious response problem. Defenders may be unable to terminate sessions, inspect settings, or restore access quickly. Meanwhile, the attacker can establish persistence and attempt lateral movement. The FBI therefore recommends more than password changes, including terminating active VPN sessions and reviewing logs for unauthorized changes.
Why can FortiBleed access become an entry point for ransomware, lateral movement, and the resale of network access?
FortiBleed access matters because a compromised firewall or SSL VPN gateway can provide a foothold inside an organization’s environment. The FBI says the attack chain has been observed as an initial entry point for ransomware affiliates. INC/Lynx ransomware and Payload ransomware are identified as groups benefiting from this access.
After gaining control, attackers establish persistence and try to move laterally through the environment. The exposed backend revealed working VPN configurations and target lists. It also showed scripts for identifying organizations and prioritizing them by revenue and network structure, helping operators select valuable victims.
The operation was not limited to direct attacks. The exposed data indicated that the operator was packaging compromised access for sale. This creates a supply chain in which one group obtains and prepares network access, while ransomware affiliates or other criminals may use it later. A single FortiBleed compromise can therefore enable several stages of abuse.
Why might patching Fortinet devices and resetting passwords alone fail to remove an attacker who has already established persistence?
Patching devices and resetting Fortinet passwords may not remove an attacker who has already changed the environment. The FBI reported incidents where attackers created administrator accounts, changed or deleted existing accounts, and established persistence. Those changes can survive a simple password reset and continue giving the attacker access.
An attacker may also retain active VPN sessions or use altered configurations and stolen authentication data. The exposed operation included scripts that extracted additional authentication data and validated credentials. This means defenders must investigate what happened on the device, not just replace one password.
The FBI recommends a broader response. Organizations should restrict external access, terminate all active VPN sessions, enforce multifactor authentication, and review logs for suspicious activity and unauthorized changes. They also recommend enforcing PBKDF2 for administrator password storage instead of legacy SHA-256 hashes, which attackers can practically crack offline.
What are password hashes, how can GPU clusters crack them offline, and why is PBKDF2 harder to crack than legacy SHA-256 storage?
A password hash is a transformed version of a password used for storage instead of keeping the original password. Attackers who steal hashes can test password guesses offline, without repeatedly interacting with the compromised device. The article says legacy SHA-256 hashes can be practically cracked this way, making stolen authentication data especially valuable.
GPU clusters perform huge numbers of calculations in parallel. In this campaign, attackers used a distributed cluster running Hashcat and Hashtopolis to test candidate passwords against stolen hashes. When a candidate produces the matching result, the attacker can use the recovered password wherever it was reused.
PBKDF2 is harder to crack because it is designed to make password processing slower and more costly. Its repeated derivation work reduces the number of guesses an attacker can try per second, including across GPUs. The FBI recommends enforcing PBKDF2 for administrator password storage instead of legacy SHA-256 hashes.
Key Facts:
📌 FortiBleed targets exposed FortiGate firewalls and SSL VPN gateways.
📌 Credentials linked to 73,932 firewall URLs were exposed.
📌 The FBI says FortiBleed attacks are still ongoing.
📌 Attackers use leaked credentials, infostealer logs, stuffing, and password spraying.
📌 Distributed GPUs crack stolen hashes offline.
📌 Scripts validate credentials and prioritize valuable targets.
📌 SOCRadar counted 86,644 compromised devices.