READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

FBI and Secret Service Confirm FortiBleed Hackers Still Breaking Into Fortinet Firewalls, Locking Out Owners

FBI and Secret Service Confirm FortiBleed Hackers Still Breaking Into Fortinet Firewalls, Locking Out Owners
The FBI and U.S. Secret Service warned Tuesday that the FortiBleed credential-theft campaign is still active, hitting more than 86,644 Fortinet FortiGate firewalls across 194 countries. Attackers aren't exploiting a software flaw, they're exploiting reused passwords and outdated encryption, then selling access to ransomware gangs like INC/Lynx.

The Warning

The FBI and the U.S. Secret Service published a joint cybersecurity advisory on Tuesday, October 6, 2026, confirming that a global credential-harvesting campaign known as FortiBleed is still actively targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, according to The Hacker News and CyberScoop.

This isn't a new vulnerability. There's no confirmed CVE or zero-day behind it, according to Hoodline. Instead, the campaign exploits old-fashioned bad password hygiene at industrial scale: reused credentials, leaked logins from prior breaches, and outdated SHA-256 password storage that attackers can crack offline.

How Bad Is It

SOCRadar has verified more than 86,644 compromised Fortinet devices spanning 194 countries, a figure cited in the federal advisory, according to The Cyber Express. That number has moved around as different researchers measured different things. CISA's initial June 18 alert cited roughly 74,000 affected devices, and Hoodline notes SOCRadar itself cautions that device counts, IP addresses, and firewall URLs aren't always measuring the same underlying set.

It may be worse than even the verified number suggests. Ensar Seker, SOCRadar's chief information security officer, told CyberScoop that a later investigation identified more than 400,000 to 450,000 firewalls targeted by the broader operation. Seker said the growing numbers "show the campaign is broader and more serious than we understood at the beginning."

How The Attack Works

According to The Cyber Express, which reviewed an exposed backend server the attackers accidentally left open, the operation runs in five stages. Scripts scan the internet for exposed FortiGate SSL VPN portals, then stuff and spray stolen credentials pulled from prior leak dumps and infostealer logs. A Go-based tool called FortigateSniffer then passively intercepts authentication traffic across two dozen protocols to harvest passwords and hashes, per The Hacker News.

Those hashes get run through a GPU-accelerated cracking cluster using Hashcat and Hashtopolis, converting stolen data into working plaintext logins. Cracked credentials are validated, filtered for honeypots, and ranked by target revenue. Attackers then create new administrator accounts on the firewall to lock in persistent access, move laterally into Active Directory, and exfiltrate data from network shares.

The FBI and Secret Service advisory warns the consequences go beyond a data breach. "Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets," the agencies said, according to CyberScoop. In some cases attackers deleted the legitimate administrator accounts entirely to block owners from regaining control while they moved deeper into the network, per The Cyber Express.

The Ransomware Connection

The advisory ties FortiBleed access directly to ransomware. Initial access brokers are reportedly selling footholds obtained through the campaign to ransomware affiliates linked to the INC/Lynx and Payload operations, according to both CyberScoop and The Cyber Express. SOCRadar said in July it had tracked at least 12 confirmed ransomware attacks stemming from FortiBleed access, according to reporting cited in a GitHub-hosted summary of The Register's coverage.

Who's At Fault Here

Some will frame this as a Fortinet product failure. FortiGate firewalls running firmware older than versions 7.6.1, 7.4.8, or 7.2.11 stored administrative credentials using legacy SHA-256 hashing instead of the stronger PBKDF2 standard, according to Trend Micro's analysis cited by Hoodline. That's a real design weakness Fortinet should have retired sooner.

But the attack chain starts with organizations reusing passwords that were already leaked elsewhere and running internet-exposed admin portals in the first place. That's not Fortinet's failure. It's basic operational security organizations skipped. The FBI and Secret Service are telling customers to restrict or eliminate internet-facing management entirely, reset all credentials, enable phishing-resistant multi-factor authentication, and review logs for unauthorized accounts.

There's also a quieter catch in the fix itself. Fortinet's own documentation states that passwords stored under the old SHA-256 scheme stay that way until an administrator logs back in after upgrading firmware, at which point they finally convert to PBKDF2, per Hoodline. Patch the software and skip that login step, and the vulnerable hash sits there untouched.

What's Unresolved

The FBI and Secret Service say they're seeking indicators of compromise from affected organizations, including attacker-controlled IP addresses and unauthorized usernames. The agencies published specific IOCs including a command-and-control server at 45.154.12.132, according to The Cyber Express. No authoritative, complete public list of every compromised IP or file hash exists yet, which means the full scope of who's still exposed depends on organizations checking their own logs and reporting back. Whether Fortinet issues a forced, automatic credential-conversion fix rather than relying on administrators to manually re-log-in remains an open question.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
The Hacker NewsFBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
center
CyberScoopAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
unknown
cyproFortiBleed Campaign Still Active
unknown
HoodlineFortiBleed Firewall Attack: FBI Warns of Mass Lockouts
unknown
The Cyber Express86,644 Firewalls in 194 Countries Breached With Stolen Passwords
unknown
GitHub[RegisterSec] FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks · Issue #74810 · SecOpsNews/news