Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

FBI says FortiBleed attacks on Fortinet firewalls continue, locking some owners out

A joint FBI and Secret Service advisory says the credential-theft campaign is still scanning Fortinet devices, and attackers sometimes delete owners' accounts to keep control.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1The FBI and Secret Service said on October 6 that FortiBleed is an active campaign against Fortinet FortiGate firewalls and SSL VPNs.
  • 2SOCRadar has verified more than 86,644 compromised devices across 194 countries, the advisory says.
  • 3Attackers may delete or change original accounts, locking owners out; access is sold to ransomware affiliates.

The news

The FBI and the U.S. Secret Service warned on October 6 that FortiBleed, a credential-theft campaign aimed at Fortinet (FTNT) FortiGate firewalls and SSL VPN gateways, remains active, and that some victims may be locked out of their own devices. The joint advisory says security firm SOCRadar has verified more than 86,644 compromised devices across 194 countries.

FortiBleed does not rely on a single software bug. According to the advisory, it exploits reused or leaked passwords and a legacy SHA-256 password storage method, which lets attackers harvest authentication data and crack it at scale. The agencies said initial findings show attackers are still scanning internet-exposed Fortinet firewalls using credentials they obtained earlier.

The advisory describes an access-broker operation whose workflow became visible after the attackers accidentally exposed their own backend server. They scanned for FortiGate SSL VPN portals, used credential stuffing and password spraying built on old Fortinet leak dumps and infostealer logs, and fed stolen password hashes into a cluster of graphics processors for offline cracking. Validated logins were sorted to prioritize high-value targets by revenue, then packaged and sold to other criminals.

The lockout risk is the newest warning. The agencies said attackers create new administrator accounts during the intrusion, and in some cases delete or change the passwords of the original accounts to keep organizations out while they move deeper into the network. The FBI and Secret Service said FortiBleed has been observed as an initial entry point for ransomware affiliates.

The Hacker News reported that SOCRadar described the 86,644 figure as confirmed-compromised devices as of June 19, 2026, not an estimate of exposed devices. The outlet also reported links to the INC and Lynx ransomware operations and at least 12 confirmed ransomware deployments traced to FortiBleed access.

The numbers

Compromised devices verified by SOCRadar
86,644+
Countries
194
Advisory date
October 6, 2026
Ransomware deployments traced (per The Hacker News)
At least 12

Why CEOs should care

For CISOs, patching alone will not fix this. Because FortiBleed runs on stolen and cracked passwords, a fully updated firewall is still exposed if its credentials were leaked. The advisory's three key actions are clear: restrict management access to trusted hosts or remove internet administration altogether; terminate all admin and VPN sessions and reset every Fortinet VPN and administrator password; and require phishing-resistant multifactor authentication on all remote access and admin accounts.

IT leaders should also audit firewall user lists for accounts nobody recognizes, since the attackers create new administrators for persistence. Teams should check logs against the indicators of compromise in the advisory and confirm they still have working admin access. Having an out-of-band recovery plan for a firewall you cannot log into is now part of incident planning.

For boards and CFOs, the firewall is the front door, and this campaign sells keys to that door to ransomware groups. Ask management whether any Fortinet devices face the internet, when their credentials were last rotated, and whether MFA is enforced on them. Cyber insurers are likely to ask the same questions.

The bigger picture

The campaign reflects a broader shift: edge devices such as firewalls and VPNs have become a favored entry point because they sit on the internet and hold the keys to internal networks. FortiBleed shows that old leaks and weak password storage can be turned into fresh access years later, which makes credential hygiene as important as software updates.

What’s next

The FBI and Secret Service asked organizations to report suspicious activity and to apply the mitigations in the advisory. Fortinet customers should rotate credentials and review admin accounts now, and watch for further indicators as the agencies update their findings.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

FortinetFortiBleedFBIUS Secret ServiceSOCRadar

Earlier coverage of Fortinet

All Fortinet coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.