Security News

FortiBleed Still Active: Attackers Are Locking Owners Out of Fortinet Firewalls and Handing Access to Ransomware Gangs

CyberScoop · 7 Oct 2026
Key Takeaway If your business uses Fortinet firewalls or VPNs, remove internet-facing administration, reset credentials, turn on multifactor authentication and check for unfamiliar admin accounts today.

The FBI and Secret Service have issued an alert that FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, remains an active threat. The agencies warn that attackers can disable accounts or change passwords, leaving organisations locked out of their own systems. This means remediation may need to go beyond standard patching and password resets.

The alert also says FortiBleed has been seen as an initial entry point for ransomware affiliates. Initial access brokers are using it to provide access to groups including INC/Lynx and Payload. Ensar Seker, chief information security officer at SOCRadar, said attackers are using stolen credentials to reach exposed Fortinet devices, create new administration accounts and, in some cases, lock the real owners out.

The scale appears larger than first thought. When the campaign was first uncovered earlier this year, SOCRadar verified more than 86,644 compromised devices across 194 countries. Its later investigation identified 400,000 to 450,000 firewalls targeted by the wider operation, though Seker noted the figures are not directly comparable over time. The agencies recommend restricting or removing internet-facing administration, resetting credentials, enabling multifactor authentication, reviewing firewall and VPN users for unauthorised changes, checking logs for signs of lateral movement, and enabling secure credential storage.

FortiBleed Fortinet ransomware credential theft VPN security

Summarised by CISO AI from CyberScoop, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.