MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-07 · via BleepingComputer

FBI warns FortiBleed intrusions still cutting off FortiGate administrators

The FBI says FortiBleed attacks are continuing against internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways. Intruders use leaked or stolen credentials, then crack password hashes with a distributed GPU setup before creating admin accounts and locking out legitimate administrators. The campaign has been linked to ransomware affiliates, including INC/Lynx and Payload.

Expanded Detail

FortiBleed surfaced in June when an exposed server yielded usernames and plaintext passwords tied to 73,932 firewall URLs in 194 countries. By July, SOCRadar connected the activity to INC and Lynx ransomware crews after examining their negotiation panels; its later tally put compromised devices at 86,644.

Intruders enter with leaked or stolen logins, infostealer output, credential stuffing, or password spraying. They pull authentication data, crack hashes offline using Hashcat and Hashtopolis on distributed GPUs, then create admin accounts, remove or alter existing ones, and seek persistence and lateral movement. Exposed backend files showed portal scanning, credential validation, honeypot filtering, target ranking by revenue/network shape, and access packaged for sale.

Context

Organizations that rely on internet-facing FortiGate SSL VPNs could face administrative lockouts, disrupted remote access, and a higher chance of ransomware follow-on. IT and security teams may spend days restoring control, while employees, contractors, and customers could encounter outages or degraded services. Because compromised access was reportedly packaged for sale, the effects may extend beyond the first victim, potentially affecting partners and supply chains that depend on the same networks.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Ongoing FortiBleed Campaign Leaves Organizations Locked Out of Their Own Firewalls · Cybersecurity
Tanium revamps security operations for attacks that mimic admin activity · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins.” Browse more stories.