Ongoing FortiBleed Campaign Leaves Organizations Locked Out of Their Own Firewalls

The FortiBleed threat campaign continues to compromise Fortinet firewall devices globally, with attackers now locking administrators out of affected systems by deleting or modifying credentials. According to an FBI and Secret Service advisory, over 86,000 FortiGate devices across 194 countries have been compromised using stolen credentials obtained from previous data breaches and information stealer logs. Attackers are systematically targeting high-value organizations, creating unauthorized accounts for persistence, and selling access to ransomware affiliates.
The FortiBleed campaign exploits a systematic approach to compromise. Attackers begin by leveraging credential databases from past security incidents and malware logs, then employ automated techniques like credential stuffing to gain initial access. Once authenticated, they extract password hashes and use specialized GPU-accelerated tools to crack them offline, refining the results through scripts designed to identify high-value targets.
The attackers' methods extend beyond simple access theft. They establish persistence by creating new administrative accounts while removing or altering existing ones, effectively locking legitimate administrators from their own infrastructure. This tactic forces organizations into complex recovery scenarios that standard security patches cannot resolve, potentially requiring extensive forensic investigation and manual system remediation.
The FortiBleed campaign may significantly impact organizations relying on Fortinet devices for network security, as compromised firewalls could enable attackers to conduct lateral movement and exfiltrate sensitive data. Critical infrastructure, financial institutions, and enterprises across 194 countries could face operational disruption if locked out of essential security appliances. The sale of access to ransomware groups raises the risk that affected organizations could face extortion demands, compounding the technical recovery burden with financial threats.