
FortiBleed is still active and locking out admins, FBI says
The credential-theft campaign against FortiGate firewalls is a way in for ransomware and cannot be fixed with patches alone, according to the FBI advisory.
The FBI and the U.S. Secret Service warned that FortiBleed, a campaign that steals credentials from Fortinet FortiGate firewalls and VPN gateways exposed to the internet, is still active and can leave administrators locked out of their own devices. The advisory, titled "FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts," is on the FBI's Internet Crime Complaint Center site. According to CyberScoop, it was issued on Tuesday, Oct. 6.
This newsroom could not read the PDF's text automatically, so what follows comes from what CyberScoop and BleepingComputer quote from it. According to that coverage, attackers can disable accounts or change passwords. The agencies say they have seen the attack chain used as "an initial entry point for ransomware affiliates." Brokers who obtain the first access sell it to groups such as INC/Lynx and Payload. They also say that remediation may take more than applying patches and resetting passwords.
There is no associated CVE. The reports describe a campaign built on credentials that were already stolen, not on a new vulnerability, so updating the device is not enough on its own. BleepingComputer says the original leak came in June, when a poorly secured server left unencrypted usernames and passwords readable for 73 932 firewall addresses.
How many devices are at stake
The reach figures come not from the FBI or Fortinet but from SOCRadar, a private threat-intelligence firm:
| SOCRadar estimate | Figure |
|---|---|
| Devices with compromised credentials verified, across 194 countries | 86 644 |
| Target firewalls, per a later investigation by its chief security officer | 400 000 to 450 000 |
What the agencies ask
According to the press that quotes the advisory, the agencies ask organizations to:
- Limit or remove administration of the device from the internet.
- Change credentials and turn on multifactor authentication.
- Look for unauthorized changes to firewall and VPN users.
- Review logs for lateral movement, meaning attackers hopping from one machine to another inside a network.
- Store credentials with secure storage.
BleepingComputer adds that administrator passwords should be stored with the PBKDF2 algorithm rather than SHA-256, which is easier to crack by trying combinations. Fortinet added it in early 2025, although third-party reports say each password is converted only when its administrator logs in again. The agencies also ask organizations to share indicators of compromise.
Still unconfirmed are whether Fortinet has published its own guidance, which this newsroom did not find, and whether organizations in Mexico are affected.



