search

LEMON BLOG

FBI Warns Ongoing FortiBleed Attacks Are Locking FortiGate VPN Administrators Out

The FBI is warning organisations that FortiBleed attacks remain active, with threat actors continuing to target exposed Fortinet FortiGate firewalls and SSL VPN gateways. In some cases, attackers are taking control of the devices and locking legitimate administrators out by deleting admin accounts or changing their passwords. The campaign is particularly concerning because compromised FortiGate systems can provide an initial foothold into corporate networks and have already been linked to ransomware activity.

According to the FBI, attackers are using previously leaked Fortinet credentials as well as usernames and passwords obtained from infostealer logs, credential-stuffing campaigns and password-spraying attacks. Once access is gained, the attackers attempt to extract additional authentication data from the compromised device. Those stolen password hashes are then cracked offline using distributed GPU infrastructure running tools such as Hashcat and Hashtopolis.

FortiBleed Is Still Being Used As An Initial Access Vector

The FBI says the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates. Groups benefiting from this access reportedly include the INC/Lynx ransomware operation and Payload ransomware. This means the campaign is not simply about stealing VPN credentials, but potentially about providing access that can later be used for lateral movement, ransomware deployment and broader network compromise.

Once an attacker gains privileged access to a FortiGate device, they may create new administrator accounts or modify existing ones to maintain control. In more aggressive cases, legitimate administrators can be locked out completely. From there, the attacker can attempt to move deeper into the organisation while preserving persistent access through the compromised gateway.

The FortiBleed Credential Leak Was Massive

FortiBleed first drew attention in June after attackers inadvertently exposed a server containing usernames and plaintext passwords associated with 73,932 firewall URLs across 194 countries. The discovery revealed the scale of the credential-harvesting operation, although the exact method used to obtain the original configuration data was not immediately clear.

The number of affected systems has reportedly continued to grow. By the latest count cited by SOCRadar, approximately 86,644 devices had been compromised. That scale makes FortiBleed one of the more significant Fortinet credential exposure incidents in recent years and explains why the same stolen data continues to be useful to attackers months later.

Ransomware Connections Emerged In July

In July, SOCRadar linked FortiBleed activity to the INC and Lynx ransomware operations after gaining access to negotiation panels associated with both groups on infrastructure used by the campaign. This provided further evidence that the stolen FortiGate access was being used or resold within the wider cybercrime ecosystem.

Compromised VPN access is especially valuable to ransomware operators because it can bypass the need for an initial malware infection. If attackers already possess valid credentials, they can sometimes enter the environment through legitimate remote-access services and then focus on privilege escalation and lateral movement. That can make detection more difficult because the initial login may resemble normal administrative activity.

Attackers Are Cracking Fortinet Password Hashes Offline

The exposed backend infrastructure also revealed how the attackers were handling stolen authentication data. Automated tools were reportedly used to scan exposed FortiGate SSL VPN portals, collect or validate credentials and identify potentially valuable targets. Password hashes extracted from compromised devices were then sent to a distributed GPU cracking environment.

Hashcat and Hashtopolis were reportedly used to process those hashes at scale. By attacking the hashes offline, the operators could try large numbers of password guesses without triggering normal login protections or account lockouts. This makes weak passwords and older hashing methods particularly dangerous once credential data has already been stolen.

The Backend Exposure Revealed A Highly Automated Operation

Details about the campaign became clearer after the attackers accidentally exposed their own backend server. The directory reportedly contained tools, scripts and datasets used throughout the operation. This included automated scanning tools, credential validation scripts, honeypot filtering and systems for identifying organisations behind exposed FortiGate appliances.

The attackers also appeared to prioritise targets based on factors such as company revenue and network structure. Working VPN configurations and target lists were also discovered, suggesting that compromised access may have been packaged and prepared for sale to other threat actors. This is consistent with the broader initial-access broker model commonly used in ransomware operations.

Locking Out Administrators Makes Recovery More Difficult

One of the more disruptive behaviours observed by the FBI involves attackers creating privileged accounts and then removing or changing the credentials of legitimate administrators. By doing this, they can effectively take control of the FortiGate device and delay the organisation's ability to respond.

Losing administrative access to a firewall or VPN gateway can significantly complicate incident recovery. These appliances often sit at critical points within the network, controlling remote access and traffic flow. If the attacker maintains control of the device while defenders are locked out, they may have additional time to establish persistence elsewhere in the environment.

Patching Alone May Not Be Enough

The FBI is warning organisations that remediation may require considerably more than simply installing updates and resetting Fortinet passwords. If an attacker already gained access before the vulnerability or credentials were addressed, malicious accounts, stolen sessions or configuration changes may still remain.

Organisations should therefore review affected devices carefully, terminate all active VPN sessions and inspect logs for unauthorised configuration changes. External access should also be restricted where possible while the investigation is underway. Multi-factor authentication should be enforced to reduce the usefulness of stolen passwords.

Stronger Password Storage Is Also Recommended

The FBI also recommends using PBKDF2 for administrator password storage rather than relying on legacy SHA-256 hashes. PBKDF2 deliberately makes password hashing more computationally expensive, which significantly increases the time required for attackers to test password guesses offline.

This is especially important in situations like FortiBleed, where attackers have access to powerful distributed GPU clusters. A password that might take relatively little time to crack when protected with a basic SHA-256 hash can become much more expensive to attack when a stronger password-derivation function is used. Improving password storage therefore adds an important additional layer of protection even if hashes are eventually stolen.

Organisations Should Review FortiGate Exposure Carefully

Companies operating internet-facing FortiGate SSL VPN services should verify whether those systems have been exposed to FortiBleed-related activity. Any device associated with previously leaked credentials should be treated as potentially compromised until administrators can confirm otherwise. Simply rotating passwords may not address attacker-created accounts, stolen tokens or other persistence mechanisms.

Logs should be reviewed for unexpected administrator creation, password changes, unfamiliar VPN connections and configuration modifications. Organisations should also look for signs of lateral movement from FortiGate-connected networks into internal systems. Given the ransomware connections already identified, the potential impact can extend well beyond the VPN appliance itself.

Final Thoughts

The continuing FortiBleed activity shows how a large credential leak can remain dangerous long after the initial exposure is discovered. Attackers are combining stolen passwords with automated scanning, GPU-based password cracking and persistent administrative access to compromise FortiGate devices at scale. The FBI's warning that the campaign is being used as an initial entry point for ransomware makes the situation especially serious.

For affected organisations, the response should go beyond routine patching. Administrators should terminate active sessions, enforce MFA, investigate suspicious configuration changes, rotate credentials and confirm that no unauthorised accounts remain. Strengthening password storage with PBKDF2 can also make future offline cracking significantly harder, reducing the value of stolen authentication data.

NIISe To Receive Real-Time Data From Interpol, Pol...
“Life Is Too Short To Support Windows Users”: Micr...

Related Posts

 

Comments 0

Loading latest comments...
Thursday, 08 October 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection