The FBI and U.S. Secret Service (USSS) on Oct. 6 warned that the FortiBleed global credential-compromise campaign was still ongoing and they should take steps to fortify their operations.
In its advisory, the FBI and USSS said teams should reduce their attack surfaces, terminate all admin and VPN sessions and reset credentials, and enable phishing-resistant multi-factor authentication (MFA).
The two federal agencies described FortiBleed as a campaign that targets internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.
In June, SOCRadar verified more than 86,644 compromised devices across 194 countries. The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, which lets threat actors harvest and crack authentication data at scale.
“Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” wrote the FBI and USSS. “In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.”
Roman Y. Sannikov, global research coordinator at iCounter, said FortiBleed shows how long a credential-harvesting campaign keeps paying off for attackers: the initial collection happened by June, but the FBI and USSS say attackers are still scanning internet-exposed Fortinet firewalls with credentials they took months ago.
“Once they're in, the tradecraft is methodical: they map Active Directory, validate Kerberos and SMB authentication, create new admin accounts for persistence, take data from network shares, and reuse stolen session cookies to skip the login prompt entirely,” said Sannikov. “That pattern fits an initial access broker building a stock of footholds to sell, and INC and Lynx ransomware operators are reportedly among the buyers.”
Justin Moore, director of adversary research at Arctic Wolf, said the latest notice from FBI and USSS regarding FortiBleed validates what we have uncovered in our previous research: attackers continue exploiting this industrialized credential operation weaponizing stolen and reused credentials to build an assembly line for establishing a foothold for broader network access.
Moore said the FBI’s warning reinforces that we should view FortiBleed as an identity-focused threat with a potentially months-long dwell window, not just a firewall issue. Organizations not only need to secure and remediate affected Fortinet devices, but they should look back across historical VPN, authentication, endpoint, and domain-controller telemetry for signs of stolen credentials, unauthorized accounts, and lateral movement.
“Patching closes the door,” said Moore. “It doesn’t remove an attacker who came through it months ago and have persistent access.”
Roy Katmor, co-founder and CEO of Orchid Security, added that FortiBleed exposes the danger of "identity dark matter" — local accounts, service identities, and application access paths outside central identity controls. Katmor said reused passwords can survive a reset elsewhere, and attackers can also create new accounts to preserve and expand their access.
“Identity dark matter makes containment difficult because it hides the full scope of compromised access,” said Katmor. “Enterprises must uncover those hidden paths and coordinate remediation across fragmented IAM tools — revoke exposed credentials and sessions, eliminate reuse, remove unauthorized accounts and excessive permissions, and verify that access is closed.”
“The news cycle moves on,” said Katmor. “The attacker’s access remains valuable until we find it and take it away."
Denis Calderone, chief technology officer at Suzu Labs, said these devices stay unpatched and targeted persistently because of a visibility problem.
Calderone said these are the firewalls nobody owns internally, such as the branch office box IT forgot about, or the poorly managed third-party infrastructure where security processes (patching for instance) just aren’t priorities, or the org that saw the CISA alert and didn't realize they were running FortiGate at all.
“These campaigns don’t age out, they just shift from the people who patched to the people who never knew they had to do something,” noted Calderone.
