FortiBleed Still Active: Attackers Are Locking Owners Out of Fortinet Firewalls and Handing Access to Ransomware Gangs
The FBI and Secret Service have issued an alert that FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, remains an active threat. The agencies warn that attackers can disable accounts or change passwords, leaving organisations locked out of their own systems. This means remediation may need to go beyond standard patching and password resets.
The alert also says FortiBleed has been seen as an initial entry point for ransomware affiliates. Initial access brokers are using it to provide access to groups including INC/Lynx and Payload. Ensar Seker, chief information security officer at SOCRadar, said attackers are using stolen credentials to reach exposed Fortinet devices, create new administration accounts and, in some cases, lock the real owners out.
The scale appears larger than first thought. When the campaign was first uncovered earlier this year, SOCRadar verified more than 86,644 compromised devices across 194 countries. Its later investigation identified 400,000 to 450,000 firewalls targeted by the wider operation, though Seker noted the figures are not directly comparable over time. The agencies recommend restricting or removing internet-facing administration, resetting credentials, enabling multifactor authentication, reviewing firewall and VPN users for unauthorised changes, checking logs for signs of lateral movement, and enabling secure credential storage.