
The FBI and Secret Service warned on Tuesday that FortiBleed, a credential-harvesting campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is still active. The Hacker News reports the Russian-speaking operation had netted more than 86,644 working device credentials across 194 countries as of June 19, 2026. The campaign was first documented by SOCRadar and Hudson Rock in June; CISA issued its own hardening guidance at that time.
According to the agencies, the attackers scan for exposed FortiGate SSL VPN portals, then use credential stuffing and password spraying with data from earlier leaks and infostealer logs. They then deploy a Go-based tool called FortigateSniffer that passively intercepts authentication traffic and collects password hashes, which are cracked offline on a GPU cluster. Cracked credentials are sorted by victim revenue and network structure, new administrator accounts are created on the firewall for persistence, and in some cases existing accounts are deleted, which can lock owners out of their own devices. The operator is suspected to be an initial access broker selling access to ransomware affiliates; the advisory ties it to INC/Lynx and Payload ransomware. The campaign came to light after the operators exposed their own backend server.
How to check if you’re affected
Affected devices are internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, especially those reachable from the internet for administration or VPN login. Per the FBI/USSS advisory and CISA’s earlier guidance:
- Review every administrator and VPN account on each FortiGate and confirm it is legitimate. Account names reported as commonly created include
fortiAdmin,forticloud-sync,fgtsecure,support_fortinet,adminsslvpnanditadmin. - Reset all VPN and administrator passwords and terminate active admin and SSL VPN sessions.
- Restrict external management of the device or remove internet administration altogether.
- Enable phishing-resistant authentication and store administrator credentials with PBKDF2, as CISA advised.
- If you find signs of compromise, isolate the device, preserve logs and artifacts, and report to the FBI and USSS.
Sources
- FBI/USSS FortiBleed advisory (IC3 PDF)
- FBI, Secret Service add to warnings of FortiBleed credential stealing campaign — The Record
- FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials — The Hacker News
- CISA: urges hardening Fortinet devices after reports of credential exposure
