FBI Warns of Escalating FortiBleed Credential Harvesting Campaign

FBI Warns of "FortiBleed" Campaign Locking Admins Out of Firewalls

HIGH
October 7, 2026
5m read
CyberattackThreat ActorRansomware

Related Entities

Threat Actors

INC LynxPayload

Organizations

Products & Tech

FortiGate

Full Report

Executive Summary

On October 6, 2026, the FBI and U.S. Secret Service issued a joint Cybersecurity Advisory (JCSA-20261006-01) regarding an escalating global campaign dubbed "FortiBleed." This operation targets internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways. Threat actors are harvesting credentials, locking out legitimate administrators, and selling the access to ransomware affiliates. The attack does not leverage a specific CVE but relies on credential stuffing and brute-force attacks against devices with poor password hygiene and no multi-factor authentication. With over 86,000 devices reportedly compromised worldwide, organizations using Fortinet products are urged to implement phishing-resistant MFA and reset all credentials immediately to mitigate the high risk of ransomware deployment.


Threat Overview

The "FortiBleed" campaign represents a significant threat to organizations relying on Fortinet security appliances. Initial access brokers are systematically targeting these devices to harvest credentials. The campaign's tactics have evolved; attackers are now actively changing passwords or disabling legitimate administrator accounts, effectively locking organizations out of their own perimeter security devices. This prevents IT staff from responding to the intrusion and makes remediation significantly more complex than a simple password reset.

The advisory confirms that access gained through FortiBleed is being sold on dark web forums to ransomware affiliates. The INC, Lynx, and Payload ransomware groups have been observed leveraging this access for initial entry into victim networks. The campaign's reach is global, with security firm SOCRadar reporting over 86,644 compromised devices across 194 countries, affecting all 16 U.S. critical infrastructure sectors.

Technical Analysis

The attack chain does not rely on a software vulnerability. Instead, it exploits weak security configurations. The primary techniques observed are:

  1. Credential Stuffing & Brute-Forcing: Attackers use leaked credentials or brute-force methods against FortiGate management interfaces and SSL VPN portals that lack multi-factor authentication. This is mapped to MITRE ATT&CK T1110 - Brute Force.
  2. Credential Interception: A custom Golang-based tool, described as a "FortiGate sniffer," is used to intercept authentication traffic and exfiltrate password hashes.
  3. Offline Password Cracking: The exfiltrated hashes are cracked offline using GPU-accelerated clusters, enabling attackers to recover plaintext passwords.
  4. Valid Account Usage: Once credentials are confirmed, attackers log in as legitimate administrators to establish persistence, lock out other users, and prepare the environment for sale. This corresponds to T1078 - Valid Accounts.
  5. Account Manipulation: Attackers disable or change passwords for legitimate accounts, a form of defense evasion and impact mapped to T1098 - Account Manipulation.

Impact Assessment

The operational impact of this campaign is severe. Being locked out of a primary firewall cripples an organization's ability to manage its network security, investigate the breach, and evict the threat actor. This provides the attacker with an uncontested foothold within the network. The subsequent sale of this access to sophisticated ransomware groups like INC means that the initial intrusion is often a precursor to a full-blown ransomware attack, leading to data encryption, exfiltration, and significant financial and operational disruption. The targeting of all 16 critical infrastructure sectors, including energy, healthcare, and government, elevates this campaign to a national security concern.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns which could indicate related activity:

Type
log_source
Value
FortiGate Event Logs
Description
Monitor for anomalous login patterns, especially from unfamiliar IP addresses or geolocations.
Type
command_line_pattern
Value
diagnose sniffer packet
Description
While a legitimate diagnostic tool, unexpected or persistent use could indicate traffic sniffing attempts.
Type
process_name
Value
(Unusual Golang binaries)
Description
Monitor for unrecognized processes running on firewall appliances, particularly those compiled with Go.
Type
event_id
Value
FortiGate Event ID 32002
Description
User login failed. A high volume of this event from a single source IP may indicate a brute-force attempt.
Type
event_id
Value
FortiGate Event ID 01004
Description
Admin user password changed. Any unexpected instance of this event should be investigated immediately.

Detection & Response

Defenders should proactively hunt for signs of compromise.

  1. Log Analysis: Continuously analyze FortiGate authentication logs for brute-force attempts (many failed logins followed by a success from the same IP), logins from anomalous geolocations, and password changes outside of normal change windows. Utilize SIEM rules to automate this detection. This aligns with D3FEND's User Geolocation Logon Pattern Analysis.
  2. Session Review: Regularly audit and terminate any suspicious or long-running administrative and VPN sessions.
  3. Incident Response: If a compromise is suspected, immediately isolate the affected FortiGate device from the network to prevent further lateral movement. Preserve logs, memory dumps, and disk images for forensic analysis. Reset all credentials associated with the device, including service accounts, API keys, and local user accounts.

Mitigation

Remediation focuses on hardening credential security and access controls.

  • Multi-Factor Authentication (MFA): This is the most critical mitigation. Enforce phishing-resistant MFA (e.g., FIDO2) for all administrative and SSL VPN user accounts. This is a direct countermeasure to credential stuffing and brute-force attacks. This aligns with D3FEND's Multi-factor Authentication.
  • Strong Password Policies: Enforce the use of long, complex, and unique passwords for all accounts. This is covered by D3FEND's Strong Password Policy.
  • Restrict Access: Limit access to the FortiGate management interface to a small set of trusted IP addresses on a dedicated management network. This hardening measure aligns with D3FEND's Network Isolation.
  • Regular Audits: Routinely audit administrative accounts, removing any that are dormant or no longer necessary.

Timeline of Events

1
October 6, 2026
The FBI and U.S. Secret Service issue a joint advisory (JCSA-20261006-01) on the 'FortiBleed' campaign.
2
October 7, 2026
This article was published

MITRE ATT&CK Mitigations

Enforcing MFA on all administrative and VPN accounts is the most effective control against credential stuffing and brute-force attacks.

Mapped D3FEND Techniques:

Implementing and enforcing strong, unique passwords makes brute-force and password reuse attacks more difficult.

Mapped D3FEND Techniques:

Restricting management interface access to a trusted IP range or dedicated management network reduces the attack surface.

Mapped D3FEND Techniques:

Audit

M1047enterprise

Regularly auditing authentication logs helps in the early detection of brute-force attempts and anomalous account activity.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

To specifically counter the 'FortiBleed' campaign, organizations must immediately deploy phishing-resistant multi-factor authentication across all FortiGate administrative interfaces and SSL-VPN portals. This is not just a recommendation but a critical, urgent requirement. Given that attackers are using credential stuffing and brute-force, MFA acts as a direct blocking mechanism. Prioritize deployment for all accounts with administrative privileges and any user accounts that provide broad network access via VPN. Use hardware tokens or authenticator apps (FIDO2/WebAuthn) over less secure methods like SMS. This directly hardens the authentication process for sslvpnd and other Fortinet daemons targeted by the attackers, rendering stolen or cracked passwords insufficient for gaining access.

In the context of the FortiBleed threat, Network Isolation should be applied to restrict all access to the FortiGate management plane. The administrative interface should never be exposed to the public internet. Create strict firewall rules that only allow access from a dedicated, hardened management VLAN or a small, static set of IP addresses corresponding to security team jump boxes. This significantly reduces the attack surface available to the initial access brokers scanning the internet for vulnerable Fortinet devices. By preventing the attackers from even reaching the login page, their brute-force and credential stuffing tools are rendered ineffective. This is a fundamental hardening practice that provides a powerful layer of defense before authentication even occurs.

Timeline of Events

1
October 6, 2026

The FBI and U.S. Secret Service issue a joint advisory (JCSA-20261006-01) on the 'FortiBleed' campaign.

Sources & References

FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users
Cybersecurity Dive (cybersecuritydive.com) •October 7, 2026
FortiBleed: SafeBreach Coverage for Joint Cybersecurity Advisory JCSA-20261006-01
Security Boulevard (securityboulevard.com) •October 7, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

credential harvestingbrute forceinitial access brokerfirewall securityFortinetJCSA

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.