Threat reportRansomwareTL-2026-3031

FortiBleed: Credential-Harvesting Campaign Compromising 86,644+ Fortinet FortiGate Devices and Locking Out Admins (FBI/USSS JCSA-20261006-01)

criticalACTIVE

FortiBleed: Credential-Harvesting Campaign Compromising (TL-2026-3031), also tracked as FortiBleed, is a critical-severity ransomware operation, first published 2026-10-07 and last reviewed 2026-10-08. It has no confirmed attribution, affects Fortinet FortiGate firewalls and SSL VPN gateways (FortiOS), maps to 18 MITRE ATT&CK techniques (T1003, T1021.001, T1040), and is covered by 9 detection rules and 31 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
31Indicators of compromise

Key facts for TL-2026-3031

Threat ID
TL-2026-3031
Also known as
FortiBleed
Severity
CRITICAL
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
critical-infrastructure, government administration, finance, health, energy, telecoms, manufacturing
Target regions
Global, india, North America, taiwan, mexico, turkey
Detection rules
9
Indicators of compromise
31
Updates
2026-10-08 · revalidated 1× · latest source

Malware and tooling in FortiBleed: Credential-Harvesting Campaign Compromising

Malware and tooling: INC Ransomware - S1139, Payload ransomware, Hashcat, Hashtopolis

How FortiBleed: Credential-Harvesting Campaign Compromising works

The FBI and U.S. Secret Service warn that the FortiBleed credential-harvesting campaign has compromised credentials for 86,644+ FortiGate firewalls and SSL VPN gateways in 194 countries and is now locking administrators out of their devices. Access is brokered to ransomware affiliates, including INC/Lynx and Payload. No CVE is involved.

FortiBleed is an incident label for a large-scale credential compromise and harvesting campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It is not a new FortiOS vulnerability. Fortinet's PSIRT assessment states: "This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory." Fortinet attributes the activity to reuse of credentials stolen in prior incidents plus brute-forcing of devices with weak password hygiene and no multi-factor authentication. SOCRadar reported 86,644 confirmed working credentials across 194 countries; Bitsight separately counted 73,000+ internet-facing FortiGate firewalls with exposed or verified administrator credentials.

On 6 October 2026 the FBI and U.S. Secret Service published joint cybersecurity advisory JCSA-20261006-01, "FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts" (ic3.gov/CSA/2026/261006.pdf). It documents attacker activity observed from 18 June to 23 July 2026, with scanning still ongoing at release. Per the advisory coverage, operators actively scan for exposed SSL VPN and management interfaces and run credential stuffing and password spraying with credentials from earlier Fortinet leak dumps and infostealer logs. They target devices that store administrator passwords with the legacy SHA-256 scheme, extract password hashes, user databases and session tokens, and crack the hashes offline on rented GPU infrastructure managed with Hashcat and Hashtopolis. Cybersecurity Dive also reports a custom Golang-based FortiGate sniffer that intercepts authentication traffic.

Once inside, actors create new local administrator accounts not previously on the device, using names that mimic legitimate support or Fortinet accounts (forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet). They enumerate Active Directory to prepare lateral movement. In some cases they delete or change the passwords of existing accounts, locking legitimate administrators out and maintaining persistence. A beacon relay on HTTPS ports 4332 and 4432, proxy nodes, a C2 server and a password-cracking server are listed as infrastructure.

The advisory characterizes the operation as an initial-access-broker network selling access to downstream operators. Affiliates of INC/Lynx and Payload ransomware have been observed using FortiBleed access as an entry point. Reporting states all 16 US critical infrastructure sectors are affected, and that more than half of compromised devices are in India, the United States, Taiwan, Mexico and Turkey. FBI guidance: isolate and collect artifacts from compromised devices, terminate all administrative and VPN sessions, reset all credentials, enforce phishing-resistant MFA, restrict management access to trusted hosts or disable internet-facing administration, verify administrator passwords use PBKDF2 rather than legacy SHA-256, and review for unexpected REST API keys and configuration changes.

MITRE ATT&CK techniques used in TL-2026-3031

Credential Access

T1003 OS Credential Dumping; T1040 Network Sniffing; T1110.001 Password Guessing; T1110.002 Password Cracking; T1110.003 Password Spraying; T1110.004 Credential Stuffing; T1552 Unsecured Credentials

Lateral Movement

T1021.001 Remote Desktop Protocol

Initial Access

T1078 Valid Accounts; T1078.001 Default Accounts; T1133 External Remote Services

Discovery

T1087 Account Discovery; T1087.002 Domain Account

Persistence

T1136.001 Local Account

Impact

T1486 Data Encrypted for Impact; T1531 Account Access Removal

Reconnaissance

T1589.001 Credentials; T1595 Active Scanning

Affected products and versions in FortiBleed: Credential-Harvesting Campaign Compromising

  • Fortinet — FortiGate firewalls and SSL VPN gateways (FortiOS)
    Vulnerable versions: Internet-exposed devices with weak, reused or leaked credentials, no MFA, or legacy SHA-256 administrator password storage
    Fixed in: No patch: credential hygiene, MFA and PBKDF2 password storage are the mitigations

Remediation for FortiBleed: Credential-Harvesting Campaign Compromising

Patches

  • No CVE or patch: the campaign abuses credentials, not a software flaw. Keep FortiOS on a current supported branch (7.4, 7.6 or 8.0 per secondary guidance)

Immediate actions

  • Isolate suspected-compromised FortiGate devices and collect logs and configuration artifacts
  • Terminate all active administrative and SSL VPN sessions
  • Reset all administrator, VPN, service, LDAP and RADIUS credentials
  • Review administrative and VPN accounts for unauthorized entries, including forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet
  • Remove unexpected REST API keys and review configuration changes against a known-good baseline
  • Block the listed IOC IP addresses and review firewall, VPN, authentication and domain controller logs for activity from them

Workarounds

  • Disable external access to the management interface
  • Use trusted-host restrictions and strong unique passwords

Longer-term hardening

  • Enforce phishing-resistant MFA on administrator and VPN accounts
  • Eliminate internet-facing administration, or restrict management to trusted hosts or local-in policies
  • Verify administrator passwords use PBKDF2 rather than legacy SHA-256 hashing
  • Hunt for Active Directory enumeration and lateral movement originating from the firewall or VPN pool

Weaknesses (CWE) in FortiBleed: Credential-Harvesting Campaign Compromising

CWE-521, CWE-798, CWE-916, CWE-1392, CWE-308

Timeline of FortiBleed: Credential-Harvesting Campaign Compromising

  • SOCRadar/Arete reporting places the start of the FortiBleed credential-harvesting operation at least as early as February 2026 (month-level precision).
  • Researcher Volodymyr 'Bob' Diachenko publicly reports an exposed dataset of ~73,932 FortiGate admin and SSL VPN credential URLs across 194 countries, found on the operators' open server; Hudson Rock names the campaign.
  • Misconfigured attacker-controlled server hosting tooling, logs and the credential dataset reported as discovered (per Security Affairs).
  • CISA issued an alert urging hardening of Fortinet devices (per Penligent analysis).
  • Start of the attacker activity window documented in FBI/USSS advisory JCSA-20261006-01 (observed 18 June to 23 July 2026); scanning and credential attacks against FortiGate SSL VPN and management interfaces.
  • Confirmed-working credential count reaches 86,644; Fortinet states the activity reuses credentials from previous incidents plus brute force, not a new vulnerability.
  • FortiBleed publicly discussed as a large credential exposure: SOCRadar reported 86,644 confirmed working FortiGate credentials in 194 countries; Bitsight counted 73,000+ exposed FortiGate firewalls. Fortinet PSIRT stated it is not a new vulnerability and attributed it to credential reuse and brute force against devices lacking MFA.
  • Singapore CSA publishes advisory AD-2026-007; UK NCSC describes FortiBleed as a global brute-force, dictionary and credential-stuffing campaign.
  • Arete and SOCRadar link FortiBleed to INC Ransom and Lynx ransomware, reporting 430,000+ targeted FortiGate devices, 110 million harvested credentials and at least 12 ransomware deployments.
  • End of the attacker source-IP activity window listed in the advisory; scanning reported as ongoing at advisory release.
  • FBI and U.S. Secret Service published JCSA-20261006-01 warning that FortiBleed operations continue and that victims report administrator lockouts via new-account creation and deletion of existing accounts; access linked to INC/Lynx and Payload ransomware affiliates.
  • Wide media coverage of the advisory (Help Net Security, Cybersecurity Dive, Cyber Security News) reiterating 86,644+ affected devices across 194 countries and listing IOCs and remediation steps.

Update history for TL-2026-3031

Sources cited for FortiBleed: Credential-Harvesting Campaign Compromising

Detection coverage for TL-2026-3031

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3031 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
31 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3031

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats