# FortiBleed: Credential-Harvesting Campaign Compromising 86,644+ Fortinet FortiGate Devices and Locking Out Admins (FBI/USSS JCSA-20261006-01)

> The FBI and U.S. Secret Service warn that the FortiBleed credential-harvesting campaign has compromised credentials for 86,644+ FortiGate firewalls and SSL VPN gateways in 194 countries and is now locking administrators out of their devices. Access is brokered to ransomware affiliates, including INC/Lynx and Payload. No CVE is involved.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-08T02:04:45.380Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3031
- **ID:** TL-2026-3031
- **Severity:** CRITICAL
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 31 (full data via the Threadlinqs MCP server — Purple tier)

## Description

FortiBleed is an incident label for a large-scale credential compromise and harvesting campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It is not a new FortiOS vulnerability. Fortinet's PSIRT assessment states: "This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory." Fortinet attributes the activity to reuse of credentials stolen in prior incidents plus brute-forcing of devices with weak password hygiene and no multi-factor authentication. SOCRadar reported 86,644 confirmed working credentials across 194 countries; Bitsight separately counted 73,000+ internet-facing FortiGate firewalls with exposed or verified administrator credentials.

On 6 October 2026 the FBI and U.S. Secret Service published joint cybersecurity advisory JCSA-20261006-01, "FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts" (ic3.gov/CSA/2026/261006.pdf). It documents attacker activity observed from 18 June to 23 July 2026, with scanning still ongoing at release. Per the advisory coverage, operators actively scan for exposed SSL VPN and management interfaces and run credential stuffing and password spraying with credentials from earlier Fortinet leak dumps and infostealer logs. They target devices that store administrator passwords with the legacy SHA-256 scheme, extract password hashes, user databases and session tokens, and crack the hashes offline on rented GPU infrastructure managed with Hashcat and Hashtopolis. Cybersecurity Dive also reports a custom Golang-based FortiGate sniffer that intercepts authentication traffic.

Once inside, actors create new local administrator accounts not previously on the device, using names that mimic legitimate support or Fortinet accounts (forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet). They enumerate Active Directory to prepare lateral movement. In some cases they delete or change the passwords of existing accounts, locking legitimate administrators out and maintaining persistence. A beacon relay on HTTPS ports 4332 and 4432, proxy nodes, a C2 server and a password-cracking server are listed as infrastructure.

The advisory characterizes the operation as an initial-access-broker network selling access to downstream operators. Affiliates of INC/Lynx and Payload ransomware have been observed using FortiBleed access as an entry point. Reporting states all 16 US critical infrastructure sectors are affected, and that more than half of compromised devices are in India, the United States, Taiwan, Mexico and Turkey. FBI guidance: isolate and collect artifacts from compromised devices, terminate all administrative and VPN sessions, reset all credentials, enforce phishing-resistant MFA, restrict management access to trusted hosts or disable internet-facing administration, verify administrator passwords use PBKDF2 rather than legacy SHA-256, and review for unexpected REST API keys and configuration changes.

## MITRE ATT&CK

- T1595 Active Scanning
- T1589.001 Credentials
- T1133 External Remote Services
- T1078 Valid Accounts
- T1110.003 Password Spraying
- T1110.004 Credential Stuffing
- T1110.002 Password Cracking
- T1003 OS Credential Dumping
- T1040 Network Sniffing
- T1136.001 Local Account
- T1087 Account Discovery
- T1531 Account Access Removal
- T1110.001 Password Guessing
- T1552 Unsecured Credentials
- T1078.001 Default Accounts
- T1087.002 Domain Account
- T1021.001 Remote Desktop Protocol
- T1486 Data Encrypted for Impact

## Sources

- [FBI Warns FortiBleed Attack Compromised 80,000+ Devices and Locked Out Admins](https://cybersecuritynews.com/fortibleed-attack-campaign-exploiting/)
- [FBI/USSS JCSA-20261006-01: FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts](https://www.ic3.gov/CSA/2026/261006.pdf)
- [FortiBleed is still active, with attackers locking admins out of Fortinet firewalls - Help Net Security](https://www.helpnetsecurity.com/2026/10/07/fortinet-fortibleed-campaign-fbi-advisory/)
- [FBI Warns of FortiBleed Attacks Leading to Lockouts, Ransomware - Decipher](https://decipher.sc/2026/10/06/fbi-warns-of-fortibleed-attacks-leading-to-lockouts-ransomware/)
- [FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users - Cybersecurity Dive](https://www.cybersecuritydive.com/news/fbi-fortibleed-credential-harvesting-attacks/832366/)
- [FortiBleed: SafeBreach Coverage for Joint Cybersecurity Advisory JCSA-20261006-01](https://securityboulevard.com/2026/10/fortibleed-safebreach-coverage-for-joint-cybersecurity-advisory-jcsa-20261006-01/)
- [FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials - GBHackers](https://gbhackers.com/fbi-warns-fortibleed-campaign-targeting-fortinet-firewalls/)
- [FortiBleed credential exposure analysis (Penligent), incl. Fortinet PSIRT statement, SOCRadar and Bitsight figures](https://www.penligent.ai/hackinglabs/?p=5689)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3031
