FortiBleed Still Active: FBI Warns of Stolen Fortinet Firewall Logins at Massive Scale
The FBI and US Secret Service have warned that the FortiBleed credential harvesting campaign is still active. It targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The agencies say attackers exploit reused or leaked credentials and legacy SHA-256 password storage, and are continuing to scan exposed firewalls using previously stolen logins. The Russian-speaking operation is estimated to have gathered more than 86,644 working device credentials across 194 countries as of 19 June 2026.
The campaign has five stages. Attackers first scan for exposed portals, then break in using credential stuffing and password spraying, drawing on earlier leak dumps and infostealer logs. They then deploy a Go-based tool called FortigateSniffer, which quietly intercepts login traffic across 24 protocols to collect credentials and password hashes. The hashes are cracked offline on a GPU-powered cluster, and the results are used to move through networks, probe Active Directory and authenticate to other systems. In the final stage, data is stolen from network shares, and stolen session cookies keep the attackers logged in.
CISA has urged FortiGate customers to enable phishing-resistant authentication, end active SSL VPN and administrative sessions, reset VPN and administrative passwords, store administrator credentials using the PBKDF2 algorithm, and review logs for suspicious activity.