
FBI and Secret Service Warn FortiBleed Hackers Are Locking Some Fortinet Customers Out of Their Own Firewalls
A joint FBI and Secret Service advisory says the credential theft campaign against internet-facing FortiGate firewalls is still scanning with stolen passwords, sometimes deletes or changes administrators' accounts so owners cannot log in, and has fed access to the INC/Lynx and Payload ransomware operations.
Noah Park, ResponseNew York6 min read
NEW YORK - The FBI and the U.S. Secret Service warned on Tuesday that FortiBleed, a credential theft campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is still running and that some victims are being locked out of their own devices. In a joint cybersecurity advisory, JCSA-20261006-01, the agencies said attackers "are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials," and that affected organizations "may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets." The advisory also said the FortiBleed attack chain "has been observed as an initial entry point for ransomware affiliates," currently including the INC/Lynx and Payload ransomware operations. For response teams, that turns a password reset into an eviction.
FortiBleed is not a software flaw. Fortinet said in June that the activity involved attackers reusing credentials from earlier incidents, which it tracks as FG-IR-26-060 and FG-IR-25-647, and brute-forcing devices with weak password hygiene and no multifactor authentication. "This is not a new Fortinet vulnerability," the company wrote. The campaign came to light in June after its operators left their own back-end server exposed with an open, browsable directory. SOCRadar, which named the campaign, said the security researcher Volodymyr "Bob" Diachenko first flagged that server, and the FBI advisory cites SOCRadar for its count of more than 86,644 compromised devices across 194 countries. SOCRadar has attributed the operation to the Lynx/INC ransomware group, which it describes as Russian-speaking. CloudSEK, which analyzed the same directory, called the operators' origin "unresolved," pointing to Russian-language artifacts in the tooling but also to password-spraying wordlists named after Persian and Arabic given names.
The advisory lays out the pipeline the exposed files revealed. The attackers scanned the internet for FortiGate SSL VPN portals, then used credential stuffing and password spraying built on earlier Fortinet leak dumps and infostealer logs. Password hashes taken from compromised devices went to a GPU cracking cluster where Hashcat and Hashtopolis ran distributed jobs, a process the agencies said is aided by legacy SHA-256 password storage. Cracked credentials were validated and sorted, with scripts filtering out honeypots, mapping organizations and ranking targets by revenue and network structure, and the attackers created new administrator accounts on the firewalls to keep their access. Inside victim networks, they enumerated Active Directory and sprayed passwords to find privileged accounts. The operation ended in "packaging and selling access, with working VPN configurations and target lists indicating the group's role as an initial-access broker," the advisory said. CloudSEK said the operator's own log showed the cracking ran on six rented Vast.ai instances totaling roughly 36 GPUs, and that the honeypot filter flagged any host that accepted more than three distinct credential pairs.

The lockouts are the new problem. "Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," the agencies wrote. Attackers create new accounts during the initial intrusion and, in certain cases, delete existing ones to keep organizations out while they attempt lateral movement. The advisory said attackers may also have exploited SSH where that port was open on the firewall, and it warned that unknown FortiGate REST API keys "may present a significant security risk," telling organizations to remove any unknown keys and refresh legitimate ones. SOCRadar's reading of the advisory was blunt: "if your runbook assumes a credential reset restores a clean state, it will fail in a lockout scenario." It advised confirming out-of-band administrative recovery for edge devices before it is needed.
For hunters, the advisory's account list is the best starting point. It names 19 usernames found on victim devices after the intrusion, including adminin, fortiAdmin, forticloud-sync, forticloud-tech, fgtsecure, fgtsec, adminsslvpn, support_fortinet, forti_support2, Technical_support and IT_Manager; Fortinet's June guidance told customers to watch for unrecognized accounts with names such as forticloud, fortiuser, fortinet-support and fortinet-tech-support. The agencies identified 45.154.12[.]132 as a command-and-control server, 154.202.59[.]169 and 103.27.186[.]156 as proxy nodes, 45.155.250[.]158 as a beacon relay, and 193.8.187[.]2, 193.8.187[.]42 and 85.11.187[.]8 as infrastructure supporting the campaign, the last running Hashtopolis. Beacons used ports including 4332 and 4432, usually over HTTPS. A further 13 addresses were seen brute-forcing or logging in with compromised accounts between June 18 and July 23. The agencies cautioned that such addresses may since have been reassigned and should be corroborated with current telemetry. They also told defenders to review firewall, VPN, authentication and domain controller logs for lateral movement, unusual access, suspicious accounts and unauthorized configuration changes.

The response order in the advisory is specific: determine which hosts were compromised and isolate them; hunt to scope the intrusion; report it to the FBI or Secret Service; then apply eviction countermeasures, using CISA's Eviction Strategies Tool, only after collecting enough hunting data to choose them well; and harden the network. The hardening list restricts external management to trusted hosts, which it rates good, a local-in policy, better, or no internet administration at all, best. It also calls for terminating all administrative and VPN sessions, resetting every Fortinet VPN and administrator password, requiring phishing-resistant multifactor authentication, comparing configurations against a known-good baseline and storing administrator credentials with PBKDF2 while removing weaker legacy hashes, which Fortinet documents for FortiOS 7.2.11 and later. Fortinet has told customers to upgrade to the latest 7.4, 7.6 or 8.0 releases and, where AD or LDAP integration is configured, to treat that account as compromised. CloudSEK added that each administrator should log in once after the upgrade to trigger re-hashing, and that LDAP, RADIUS and service account credentials stored in exported configurations should be rotated. The agencies said they do not encourage paying ransoms.
How many organizations were actually breached is disputed. CloudSEK, which reconstructed the campaign from 319 files in the open directory, said the widely repeated figure of about 21,000 affected domains traces to 21,632 entries in the attackers' FortiGuard registration database, a catalog it said is not a verified breach list. Only 918 organizations showed evidence of Kerberos traffic captured from inside their networks, CloudSEK said, and 148 had Kerberos hashes cracked and Active Directory credentials verified. It also found credentials for non-Fortinet devices mixed into the data. "Appearing in the dataset is a reason to investigate, not proof of compromise," CloudSEK wrote. Both SOCRadar and CloudSEK sell threat intelligence. SOCRadar offers a free FortiBleed lookup tool, and CloudSEK argued, without naming a company, that publishing attribution based on registration emails alongside a free domain lookup tool without that caveat "conflates marketing with disclosure." Neither dispute changes the advisory's point for defenders. SOCRadar noted that the agencies' phrase "currently including" means the list of ransomware buyers can grow, and it urged treating any confirmed FortiBleed exposure "as a potential precursor to multiple ransomware outcomes, not one."

Sources:
- FBI IC3: Joint cybersecurity advisory JCSA-20261006-01 (FBI and U.S. Secret Service, Oct 6, 2026)
- Fortinet: Analysis of Reported Credential Compromise of FortiGate Devices (Fortinet PSIRT, June 19, 2026)
- SOCRadar: FortiBleed: The Campaign That Cracked 86,644 Firewalls (SOCRadar, June 16, 2026)
- SOCRadar: FortiBleed Is Still Active, Locking Organizations Out (SOCRadar, Oct 7, 2026)
- CloudSEK: Inside the FortiBleed Open Directory (CloudSEK, June 2026)
- Fortinet: Enforcing PBKDF2 as hash function for administrator accounts (Fortinet Community)
Noah Park covers incident response and blue-team operations for SOCtember from New York.
Related stories
Threat Intel
FBI Seizes Integrity Tech Hacking Tools as Allies Detail How China-Linked Hackers Steal Government Email
Response
Check Point VPN Flaw Is a Remote-Access Control-Plane Incident, Not Only a Gateway Patch
Response
Citrix Patches NetScaler SAML Zero-Day CVE-2026-88779 After Attacks Reboot Freshly Patched Appliances
Response
Did You Know: Patching a KEV Host Before Collecting Evidence Can Erase the Intrusion Trail
Response
Poisoned Tensorlake npm Release Hid a Worm That Deletes Home Directories if Victims Revoke the Stolen Token
Detection