MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-07 · via Help Net Security

Ongoing FortiBleed Campaign Leaves Organizations Locked Out of Their Own Firewalls

Image via Help Net Security
Image via Help Net Security

The FortiBleed threat campaign continues to compromise Fortinet firewall devices globally, with attackers now locking administrators out of affected systems by deleting or modifying credentials. According to an FBI and Secret Service advisory, over 86,000 FortiGate devices across 194 countries have been compromised using stolen credentials obtained from previous data breaches and information stealer logs. Attackers are systematically targeting high-value organizations, creating unauthorized accounts for persistence, and selling access to ransomware affiliates.

Expanded Detail

The FortiBleed campaign exploits a systematic approach to compromise. Attackers begin by leveraging credential databases from past security incidents and malware logs, then employ automated techniques like credential stuffing to gain initial access. Once authenticated, they extract password hashes and use specialized GPU-accelerated tools to crack them offline, refining the results through scripts designed to identify high-value targets.

The attackers' methods extend beyond simple access theft. They establish persistence by creating new administrative accounts while removing or altering existing ones, effectively locking legitimate administrators from their own infrastructure. This tactic forces organizations into complex recovery scenarios that standard security patches cannot resolve, potentially requiring extensive forensic investigation and manual system remediation.

Context

The FortiBleed campaign may significantly impact organizations relying on Fortinet devices for network security, as compromised firewalls could enable attackers to conduct lateral movement and exfiltrate sensitive data. Critical infrastructure, financial institutions, and enterprises across 194 countries could face operational disruption if locked out of essential security appliances. The sale of access to ransomware groups raises the risk that affected organizations could face extortion demands, compounding the technical recovery burden with financial threats.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “FortiBleed is still active, with attackers locking admins out of Fortinet firewalls.” Browse more stories.