Malware & Threats

FortiBleed Attackers Locking Victims Out of Fortinet Devices

Attackers are creating new accounts and deleting existing ones and passwords to prevent legitimate access.

Fortinet attack

The FortiBleed credential-harvesting and access-broker campaign is still active, and attackers are locking organizations out of their Fortinet devices.

Targeting internet-accessible Fortinet FortiGate firewalls and SSL VPN appliances, the campaign started in June.

Fortinet’s analysis of the attacks revealed that the attackers were using previously compromised credentials and brute-force techniques to take over poorly protected devices.

Within a week, the attacks hit over 86,000 Fortinet devices in 190 countries, and a Russian initial access broker was blamed for the campaign.

Now, SOCRadar says it has confirmed the compromise of approximately 86,644 devices in 194 countries. The attackers are searching for accessible firewalls and using compromised credentials to take them over.

“[This] is a count of confirmed-compromised devices, not an exposure estimate. Devices breached months ago remain in the actors’ validated inventory,” SOCRadar notes.

Advertisement. Scroll to continue reading.

In a joint advisory (PDF) released this week, the FBI and the US Secret Service (USSS) warn that the hackers have been locking organizations out of their Fortinet appliances by changing passwords and deleting accounts.

“Some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment,” the advisory reads.

The hackers have been observed scanning for exposed SSL VPN portals, harvesting credentials from infostealer logs and previous dumps, cracking hashed credentials offline, mapping the attack surface to evade honeypots, using verified credentials to compromise devices, and selling working VPN configs and target lists to other threat actors.

The FBI and USSS recommend that affected organizations identify the compromised hosts, scope the intrusion, evict the attackers, harden protections to prevent additional threat actor activity, and report the intrusions.

To reduce the attack surface, organizations should restrict management access, reset all Fortinet VPN and administrative passwords, implement phishing-resistant multifactor authentication (MFA), review firewall and VPN users and configurations, review and validate API keys, review logs for suspicious activity, and ensure credentials are stored securely.

Related: Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Related: Anthropic Introduces 3-Tier Cyber Verification Program for AI Access

Related: Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies

Related: FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

Related Content

Vulnerabilities

CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system.

Malware & Threats

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Network Security

The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.

Funding/M&A

Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems.

Vulnerabilities

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.

Vulnerabilities

A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code.

Network Security

Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version