The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.
"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale," the agencies said. "Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials."
FortiBleed was first documented by SOCRadar and Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In all, the Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026.
"The scale under discussion, more than 86,644 compromised devices across 194 countries, is a count of confirmed-compromised devices, not an exposure estimate," SOCRadar said. "Devices breached months ago remain in the actors’ validated inventory."
The campaign subsequently prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to urge Fortinet customers with FortiGate appliances to enable phishing-resistant authentication, terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrative passwords, use the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials, and review logs for signs of suspicious activity.
FortiBleed is a five-stage campaign that conducts widespread reconnaissance to identify exposed portals, gain access to those devices using credential stuffing and password spraying based on data obtained from prior leak dumps and infostealer logs, and then deploy a Go-based tool called FortigateSniffer to passively intercept authentication traffic across 24 protocols and harvest credentials and password hashes.
The password hashes are then routed to a GPU-accelerated cracking cluster that uses Hashmat and Hashtopolis for offline cracking, after which they are used to facilitate lateral movement, Active Directory enumeration, Kerberos validation, and SMB authentication. In the final stage, sensitive data from network shares is exfiltrated while stolen session cookies are used to maintain persistent, authenticated access.
"Cracked credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure," the agencies said. "New administrative accounts were created on the firewall to maintain persistence."
With the verified credentials in hand, the attackers have been found to move deeper into victim environments, conduct enumeration, and conduct password spraying to expand access and identify privileged accounts.
In addition, the initial access is used to add new accounts to the system as a way of maintaining persistence on the appliance. Some of the commonly identified compromised account names is listed below -
- adminin
- fortiAdmin
- forticloud-sync
- admin
- fgtsecure
- pakedge
- forticloud-tech
- districtadmin
- system_config
- gttadmin
- roadmin
- itadmin
- Technical_support
- adminsslvpn
- IT_Manager
- my_admin
- support_fortinet
- fgtsec
- forti_support2
The adversary is suspected to be an initial access broker that packages the stolen information and sells it to downstream threat actors. This is evidenced by the fact that operator overlaps tying FortiBleed to INC and Lynx ransomware operations, likely indicating that the access is being abused for ransomware deployment.
"Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," the FBI and USSS warned.
"During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment."
If potential compromise is detected, organizations are advised to isolate the affected devices, collect necessary artifacts and logs, report the incident to the FBI and USSS, and apply relevant countermeasures to mitigate the threat.
Update
In a statement shared with The Hacker News, SOCRadar CISO Ensar Seker said the latest advisory reinforces their assessment that "FortiBleed should be treated as an active access operation, not as a one-time credential leak."
"The continued scanning with previously compromised credentials, creation of unauthorized administrative accounts, and reported lockouts show that the operators are still attempting to preserve and expand access," Seker added. "The available evidence clearly supports continued credential validation, reuse, and attempted compromise."
Besides uncovering a direct operational link between FortiBleed-derived access and the INC/Lynx ecosystem, the threat intelligence company said it has confirmed at least 12 ransomware deployments stemming from this access, resulting in hundreds of endpoints getting encrypted.
The fact that initial-access brokers using the FortiBleed attack chain have also supplied access to Payload ransomware affiliates is evidence that the operation is financially motivated and part of a broader ransomware supply chain rather than serving a single ransomware brand.
"The key point is that exposed credentials do not become harmless with age," Seker said. "If they remain valid, or if attackers have already created persistent accounts on the appliance, they can continue to provide an entry point months after the original harvesting activity."
"Organizations should therefore treat possible exposure as a compromise scenario: restrict external management, terminate active sessions, rotate administrative and VPN credentials, review all local and API accounts, enforce phishing-resistant MFA, and investigate downstream activity rather than relying on patching alone."
Dray Agha, senior manager of Tactical Response at Huntress, is recommending that organizations enforce multi-factor authentication for all remote access, audit their systems for newly created accounts, and remove internet-facing administration interfaces.
"Targeting edge devices like VPNs and firewalls is nothing new, but this FortiBleed campaign stands out because of the contrast between the silent initial access and the aggressive takeover that follows," Ben Bernstein, manager of the Cybersecurity Advisors Team at Huntress, said in a statement.
"Attackers are stealing configuration files, cracking password hashes offline on their own hardware, and logging in on the first try without generating a single failed login alert. Once inside, they abandon the usual initial access broker playbook of staying quiet. Instead, they confidently change the administrator passwords, lock the actual IT team out of their own equipment, and hand the keys directly to ransomware groups like INC and Payload."
"When you no longer have access to your own firewall, you cannot just apply a software patch and move on. These attackers know organizations will have to physically factory reset and rebuild the hardware before the encryption starts."
(The story has been updated after publication to include additional information from SOCRadar and Huntress.)




