FBI warns FortiBleed intrusions still cutting off FortiGate administrators
The FBI says FortiBleed attacks are continuing against internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways. Intruders use leaked or stolen credentials, then crack password hashes with a distributed GPU setup before creating admin accounts and locking out legitimate administrators. The campaign has been linked to ransomware affiliates, including INC/Lynx and Payload.
FortiBleed surfaced in June when an exposed server yielded usernames and plaintext passwords tied to 73,932 firewall URLs in 194 countries. By July, SOCRadar connected the activity to INC and Lynx ransomware crews after examining their negotiation panels; its later tally put compromised devices at 86,644.
Intruders enter with leaked or stolen logins, infostealer output, credential stuffing, or password spraying. They pull authentication data, crack hashes offline using Hashcat and Hashtopolis on distributed GPUs, then create admin accounts, remove or alter existing ones, and seek persistence and lateral movement. Exposed backend files showed portal scanning, credential validation, honeypot filtering, target ranking by revenue/network shape, and access packaged for sale.
Organizations that rely on internet-facing FortiGate SSL VPNs could face administrative lockouts, disrupted remote access, and a higher chance of ransomware follow-on. IT and security teams may spend days restoring control, while employees, contractors, and customers could encounter outages or degraded services. Because compromised access was reportedly packaged for sale, the effects may extend beyond the first victim, potentially affecting partners and supply chains that depend on the same networks.