Threat reportRansomwareTL-2026-3031
FortiBleed: Credential-Harvesting Campaign Compromising 86,644+ Fortinet FortiGate Devices and Locking Out Admins (FBI/USSS JCSA-20261006-01)
FortiBleed: Credential-Harvesting Campaign Compromising (TL-2026-3031), also tracked as FortiBleed, is a critical-severity ransomware operation, first published 2026-10-07 and last reviewed 2026-10-08. It has no confirmed attribution, affects Fortinet FortiGate firewalls and SSL VPN gateways (FortiOS), maps to 18 MITRE ATT&CK techniques (T1003, T1021.001, T1040), and is covered by 9 detection rules and 31 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 31Indicators of compromise
Key facts for TL-2026-3031
- Threat ID
- TL-2026-3031
- Also known as
- FortiBleed
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- critical-infrastructure, government administration, finance, health, energy, telecoms, manufacturing
- Target regions
- Global, india, North America, taiwan, mexico, turkey
- Detection rules
- 9
- Indicators of compromise
- 31
- Updates
- 2026-10-08 · revalidated 1× · latest source
Malware and tooling in FortiBleed: Credential-Harvesting Campaign Compromising
Malware and tooling: INC Ransomware - S1139, Payload ransomware, Hashcat, Hashtopolis
How FortiBleed: Credential-Harvesting Campaign Compromising works
The FBI and U.S. Secret Service warn that the FortiBleed credential-harvesting campaign has compromised credentials for 86,644+ FortiGate firewalls and SSL VPN gateways in 194 countries and is now locking administrators out of their devices. Access is brokered to ransomware affiliates, including INC/Lynx and Payload. No CVE is involved.
FortiBleed is an incident label for a large-scale credential compromise and harvesting campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It is not a new FortiOS vulnerability. Fortinet's PSIRT assessment states: "This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory." Fortinet attributes the activity to reuse of credentials stolen in prior incidents plus brute-forcing of devices with weak password hygiene and no multi-factor authentication. SOCRadar reported 86,644 confirmed working credentials across 194 countries; Bitsight separately counted 73,000+ internet-facing FortiGate firewalls with exposed or verified administrator credentials.
On 6 October 2026 the FBI and U.S. Secret Service published joint cybersecurity advisory JCSA-20261006-01, "FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts" (ic3.gov/CSA/2026/261006.pdf). It documents attacker activity observed from 18 June to 23 July 2026, with scanning still ongoing at release. Per the advisory coverage, operators actively scan for exposed SSL VPN and management interfaces and run credential stuffing and password spraying with credentials from earlier Fortinet leak dumps and infostealer logs. They target devices that store administrator passwords with the legacy SHA-256 scheme, extract password hashes, user databases and session tokens, and crack the hashes offline on rented GPU infrastructure managed with Hashcat and Hashtopolis. Cybersecurity Dive also reports a custom Golang-based FortiGate sniffer that intercepts authentication traffic.
Once inside, actors create new local administrator accounts not previously on the device, using names that mimic legitimate support or Fortinet accounts (forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet). They enumerate Active Directory to prepare lateral movement. In some cases they delete or change the passwords of existing accounts, locking legitimate administrators out and maintaining persistence. A beacon relay on HTTPS ports 4332 and 4432, proxy nodes, a C2 server and a password-cracking server are listed as infrastructure.
The advisory characterizes the operation as an initial-access-broker network selling access to downstream operators. Affiliates of INC/Lynx and Payload ransomware have been observed using FortiBleed access as an entry point. Reporting states all 16 US critical infrastructure sectors are affected, and that more than half of compromised devices are in India, the United States, Taiwan, Mexico and Turkey. FBI guidance: isolate and collect artifacts from compromised devices, terminate all administrative and VPN sessions, reset all credentials, enforce phishing-resistant MFA, restrict management access to trusted hosts or disable internet-facing administration, verify administrator passwords use PBKDF2 rather than legacy SHA-256, and review for unexpected REST API keys and configuration changes.
MITRE ATT&CK techniques used in TL-2026-3031
Credential Access
T1003 OS Credential Dumping; T1040 Network Sniffing; T1110.001 Password Guessing; T1110.002 Password Cracking; T1110.003 Password Spraying; T1110.004 Credential Stuffing; T1552 Unsecured Credentials
Lateral Movement
T1021.001 Remote Desktop Protocol
Initial Access
T1078 Valid Accounts; T1078.001 Default Accounts; T1133 External Remote Services
Discovery
T1087 Account Discovery; T1087.002 Domain Account
Persistence
Impact
T1486 Data Encrypted for Impact; T1531 Account Access Removal
Reconnaissance
Affected products and versions in FortiBleed: Credential-Harvesting Campaign Compromising
- Fortinet — FortiGate firewalls and SSL VPN gateways (FortiOS)
Vulnerable versions: Internet-exposed devices with weak, reused or leaked credentials, no MFA, or legacy SHA-256 administrator password storage
Fixed in: No patch: credential hygiene, MFA and PBKDF2 password storage are the mitigations
Remediation for FortiBleed: Credential-Harvesting Campaign Compromising
Patches
- No CVE or patch: the campaign abuses credentials, not a software flaw. Keep FortiOS on a current supported branch (7.4, 7.6 or 8.0 per secondary guidance)
Immediate actions
- Isolate suspected-compromised FortiGate devices and collect logs and configuration artifacts
- Terminate all active administrative and SSL VPN sessions
- Reset all administrator, VPN, service, LDAP and RADIUS credentials
- Review administrative and VPN accounts for unauthorized entries, including forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet
- Remove unexpected REST API keys and review configuration changes against a known-good baseline
- Block the listed IOC IP addresses and review firewall, VPN, authentication and domain controller logs for activity from them
Workarounds
- Disable external access to the management interface
- Use trusted-host restrictions and strong unique passwords
Longer-term hardening
- Enforce phishing-resistant MFA on administrator and VPN accounts
- Eliminate internet-facing administration, or restrict management to trusted hosts or local-in policies
- Verify administrator passwords use PBKDF2 rather than legacy SHA-256 hashing
- Hunt for Active Directory enumeration and lateral movement originating from the firewall or VPN pool
Weaknesses (CWE) in FortiBleed: Credential-Harvesting Campaign Compromising
Timeline of FortiBleed: Credential-Harvesting Campaign Compromising
- SOCRadar/Arete reporting places the start of the FortiBleed credential-harvesting operation at least as early as February 2026 (month-level precision).
- Researcher Volodymyr 'Bob' Diachenko publicly reports an exposed dataset of ~73,932 FortiGate admin and SSL VPN credential URLs across 194 countries, found on the operators' open server; Hudson Rock names the campaign.
- Misconfigured attacker-controlled server hosting tooling, logs and the credential dataset reported as discovered (per Security Affairs).
- CISA issued an alert urging hardening of Fortinet devices (per Penligent analysis).
- Start of the attacker activity window documented in FBI/USSS advisory JCSA-20261006-01 (observed 18 June to 23 July 2026); scanning and credential attacks against FortiGate SSL VPN and management interfaces.
- Confirmed-working credential count reaches 86,644; Fortinet states the activity reuses credentials from previous incidents plus brute force, not a new vulnerability.
- FortiBleed publicly discussed as a large credential exposure: SOCRadar reported 86,644 confirmed working FortiGate credentials in 194 countries; Bitsight counted 73,000+ exposed FortiGate firewalls. Fortinet PSIRT stated it is not a new vulnerability and attributed it to credential reuse and brute force against devices lacking MFA.
- Singapore CSA publishes advisory AD-2026-007; UK NCSC describes FortiBleed as a global brute-force, dictionary and credential-stuffing campaign.
- Arete and SOCRadar link FortiBleed to INC Ransom and Lynx ransomware, reporting 430,000+ targeted FortiGate devices, 110 million harvested credentials and at least 12 ransomware deployments.
- End of the attacker source-IP activity window listed in the advisory; scanning reported as ongoing at advisory release.
- FBI and U.S. Secret Service published JCSA-20261006-01 warning that FortiBleed operations continue and that victims report administrator lockouts via new-account creation and deletion of existing accounts; access linked to INC/Lynx and Payload ransomware affiliates.
- Wide media coverage of the advisory (Help Net Security, Cybersecurity Dive, Cyber Security News) reiterating 86,644+ affected devices across 194 countries and listing IOCs and remediation steps.
Update history for TL-2026-3031
- 2026-10-08 — FortiBleed: Large-Scale Credential Harvesting Campaign Compromising 86,000+ Fortinet FortiGate Firewalls and VPN Gateways (FBI/Secret Service Advisory): What changed No change to severity (CRITICAL), exploitability (ACTIVE) or status (ACTIVE). Attribution confidence LOW → MEDIUM based on multi-vendor reporting (SOCRadar, Arete, Recorded Future, CSA) tying the operation to a Russian-speaking
Sources cited for FortiBleed: Credential-Harvesting Campaign Compromising
- FBI Warns FortiBleed Attack Compromised 80,000+ Devices and Locked Out Admins
- FBI/USSS JCSA-20261006-01: FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts
- FortiBleed is still active, with attackers locking admins out of Fortinet firewalls - Help Net Security
- FBI Warns of FortiBleed Attacks Leading to Lockouts, Ransomware - Decipher
- FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users - Cybersecurity Dive
- FortiBleed: SafeBreach Coverage for Joint Cybersecurity Advisory JCSA-20261006-01
- FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials - GBHackers
- FortiBleed credential exposure analysis (Penligent), incl. Fortinet PSIRT statement, SOCRadar and Bitsight figures
Detection coverage for TL-2026-3031
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3031 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-3031
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.