FBI Warns FortiBleed Attacks Continue After 86,000+ Devices Compromised

The FBI warns FortiBleed attacks continue after 86,000+ Fortinet devices were compromised. See what security teams should investigate beyond applying patches.

Written By
Kezia Jungco
Kezia Jungco
Oct 8, 2026
3 minute read
Fortinet network appliance in a server rack with connected blue and gray Ethernet cables and illuminated status lights.

The FBI warns that FortiBleed attacks continue to threaten Fortinet devices, even after security updates. Image generated via ChatGPT

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Fortinet administrators who patched their firewalls may still have a problem: attackers could already be inside. The FBI and US Secret Service warn that FortiBleed operators are still trying stolen credentials and, in some cases, locking legitimate administrators out of their devices.

In an Oct. 6 advisory, the agencies cited SOCRadar’s earlier findings of more than 86,644 compromised Fortinet devices across 194 countries, warning that attackers continue to use previously stolen credentials.

FortiBleed is a credential-compromise campaign targeting internet-facing FortiGate firewalls and SSL VPN gateways. Fortinet says the activity involves reused credentials and brute-force attacks rather than a newly disclosed vulnerability.

For security teams, the immediate question is whether attackers still have working access, not simply whether the latest updates are installed.

Stolen credentials give FortiBleed attackers network access

According to the FBI and Secret Service, attackers scan exposed FortiGate VPN portals and test credentials from previous leaks and infostealer logs. They also harvest password hashes and use GPU-powered tools to crack them offline, exploiting legacy SHA-256 password storage.

Once inside, intruders can create administrator accounts, investigate Active Directory and try to reach other systems. Some have changed or deleted legitimate accounts, locking administrators out while attackers retain access.

The stakes go beyond the firewall. SOCRadar told The Hacker News it had confirmed at least 12 ransomware deployments stemming from FortiBleed-derived access, with hundreds of endpoints encrypted. Federal investigators also linked access brokers using the attack chain to INC/Lynx and Payload ransomware affiliates.

Unauthorized accounts can remain after patching

“Patching closes the door,” Justin Moore, director of adversary research at Arctic Wolf, told SC Media. His point was that an attacker who created another administrator account or stole valid credentials may still have a way in after the device is updated.

Moore urged organizations to review historical VPN, authentication, endpoint, and domain-controller activity, not just current firewall settings. 

Advertisement

SC Media also highlighted a visibility problem: branch-office appliances and third-party-managed devices may be overlooked during routine security work.

FortiGate administrators should audit accounts, sessions, and logs

Organizations using FortiGate firewalls and SSL VPNs should review exposed gateways, even if they have already patched them. The FBI and Secret Service recommend:

  • Find exposed devices. Inventory internet-facing FortiGate management interfaces and VPN gateways, including branch locations. Remove public administrative access where possible or restrict it to trusted sources.
  • Cut off unauthorized access. Terminate administrator and VPN sessions, reset passwords, and enforce phishing-resistant MFA. Verify administrator accounts and API keys, remove unauthorized accounts and unknown keys, and refresh legitimate API keys.
  • Investigate earlier activity. Compare configurations with known-good versions and examine firewall, VPN, authentication, and domain-controller logs for suspicious access or lateral movement. Follow Fortinet’s version-specific guidance to ensure administrator passwords use PBKDF2 and remove retained legacy SHA-256 hashes. A firmware upgrade alone does not complete this process.

If investigators find signs of compromise, the advisory recommends isolating affected systems, preserving evidence, and planning how to remove the attackers. Its listed IP addresses and usernames are leads to investigate, not proof of compromise on their own.

Security teams should also watch for suspicious accounts or VPN sessions returning after credentials are reset. FortiBleed-related access has already reached ransomware operators, so confirming a firewall is updated is only one part of the job. Organizations need to establish whether anyone got in, what they accessed, and whether any route back into the network remains.

Read more: Organizations using Fortinet email gateways should also review the affected versions and mitigation guidance for the actively exploited FortiMail zero-day.

Kezia Jungco

Kezia Jungco is a staff writer with five years of hands-on experience testing and analyzing generative AI platforms, chatbots, and NLP tools. She writes in-depth coverage for both enterprise and consumer audiences, focusing on artificial intelligence, data analytics, CRM solutions, cloud infrastructure, cybersecurity, and emerging tech trends. Her work appears in TechRepublic, eWEEK, Datamation, TechnologyAdvice, and Selling Signals.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.