The FortiBleed credential-harvesting and access-broker campaign is still active, and attackers are locking organizations out of their Fortinet devices.
Targeting internet-accessible Fortinet FortiGate firewalls and SSL VPN appliances, the campaign started in June.
Fortinet’s analysis of the attacks revealed that the attackers were using previously compromised credentials and brute-force techniques to take over poorly protected devices.
Within a week, the attacks hit over 86,000 Fortinet devices in 190 countries, and a Russian initial access broker was blamed for the campaign.
Now, SOCRadar says it has confirmed the compromise of approximately 86,644 devices in 194 countries. The attackers are searching for accessible firewalls and using compromised credentials to take them over.
“[This] is a count of confirmed-compromised devices, not an exposure estimate. Devices breached months ago remain in the actors’ validated inventory,” SOCRadar notes.
In a joint advisory (PDF) released this week, the FBI and the US Secret Service (USSS) warn that the hackers have been locking organizations out of their Fortinet appliances by changing passwords and deleting accounts.
“Some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment,” the advisory reads.
The hackers have been observed scanning for exposed SSL VPN portals, harvesting credentials from infostealer logs and previous dumps, cracking hashed credentials offline, mapping the attack surface to evade honeypots, using verified credentials to compromise devices, and selling working VPN configs and target lists to other threat actors.
The FBI and USSS recommend that affected organizations identify the compromised hosts, scope the intrusion, evict the attackers, harden protections to prevent additional threat actor activity, and report the intrusions.
To reduce the attack surface, organizations should restrict management access, reset all Fortinet VPN and administrative passwords, implement phishing-resistant multifactor authentication (MFA), review firewall and VPN users and configurations, review and validate API keys, review logs for suspicious activity, and ensure credentials are stored securely.
Related: Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
Related: Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
Related: Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies
Related: FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
