Security News

FortiBleed: Over 86,000 Fortinet Firewalls Compromised in Months-Long Credential Theft Campaign

The Record · 7 Oct 2026
Key Takeaway If your business uses Fortinet firewalls or VPNs, review every account on the devices today, remove any you do not recognise, and make sure no one reuses passwords that could already be leaked.

The FBI and Secret Service have issued an advisory about FortiBleed, an ongoing campaign that has compromised more than 86,000 internet-facing Fortinet FortiGate firewalls and VPN gateways in 194 countries. The agencies say the attacks have continued for months and rely on reused or leaked credentials, which allow attackers to harvest and crack authentication data at scale.

According to the advisory, attackers scanned the internet for exposed FortiGate SSL VPN portals and used automated scripts to find reachable devices. They then gathered large volumes of credentials through credential stuffing and password spraying. Stolen logins were validated and sorted by a victim's revenue or network structure. Attackers also created new accounts on firewall devices to keep their access. Some sold that access, while others used it themselves. Initial access brokers are offering it to affiliates of the INC/Lynx and Payload ransomware groups, and the agencies say FortiBleed has been observed as an entry point for ransomware.

The campaign came to light after the hackers exposed their own backend server, giving investigators a rare view of their workflow. The agencies warn that victims may be locked out if attackers disable accounts or change passwords, so recovery may need more than standard patching and password resets. They advise organisations to review all Fortinet accounts and verify that each one is legitimate.

FortiBleed Fortinet credential stuffing ransomware VPN security

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.