On October 6, 2026, the FBI and U.S. Secret Service issued a joint Cybersecurity Advisory (JCSA-20261006-01) regarding an escalating global campaign dubbed "FortiBleed." This operation targets internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways. Threat actors are harvesting credentials, locking out legitimate administrators, and selling the access to ransomware affiliates. The attack does not leverage a specific CVE but relies on credential stuffing and brute-force attacks against devices with poor password hygiene and no multi-factor authentication. With over 86,000 devices reportedly compromised worldwide, organizations using Fortinet products are urged to implement phishing-resistant MFA and reset all credentials immediately to mitigate the high risk of ransomware deployment.
The "FortiBleed" campaign represents a significant threat to organizations relying on Fortinet security appliances. Initial access brokers are systematically targeting these devices to harvest credentials. The campaign's tactics have evolved; attackers are now actively changing passwords or disabling legitimate administrator accounts, effectively locking organizations out of their own perimeter security devices. This prevents IT staff from responding to the intrusion and makes remediation significantly more complex than a simple password reset.
The advisory confirms that access gained through FortiBleed is being sold on dark web forums to ransomware affiliates. The INC, Lynx, and Payload ransomware groups have been observed leveraging this access for initial entry into victim networks. The campaign's reach is global, with security firm SOCRadar reporting over 86,644 compromised devices across 194 countries, affecting all 16 U.S. critical infrastructure sectors.
The attack chain does not rely on a software vulnerability. Instead, it exploits weak security configurations. The primary techniques observed are:
T1110 - Brute Force.T1078 - Valid Accounts.T1098 - Account Manipulation.The operational impact of this campaign is severe. Being locked out of a primary firewall cripples an organization's ability to manage its network security, investigate the breach, and evict the threat actor. This provides the attacker with an uncontested foothold within the network. The subsequent sale of this access to sophisticated ransomware groups like INC means that the initial intrusion is often a precursor to a full-blown ransomware attack, leading to data encryption, exfiltration, and significant financial and operational disruption. The targeting of all 16 critical infrastructure sectors, including energy, healthcare, and government, elevates this campaign to a national security concern.
No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were provided in the source articles.
Security teams may want to hunt for the following patterns which could indicate related activity:
diagnose sniffer packet32002User login failed. A high volume of this event from a single source IP may indicate a brute-force attempt.01004Admin user password changed. Any unexpected instance of this event should be investigated immediately.Defenders should proactively hunt for signs of compromise.
User Geolocation Logon Pattern Analysis.Remediation focuses on hardening credential security and access controls.
Multi-factor Authentication.Strong Password Policy.Network Isolation.Enforcing MFA on all administrative and VPN accounts is the most effective control against credential stuffing and brute-force attacks.
Mapped D3FEND Techniques:
Implementing and enforcing strong, unique passwords makes brute-force and password reuse attacks more difficult.
Mapped D3FEND Techniques:
Restricting management interface access to a trusted IP range or dedicated management network reduces the attack surface.
Mapped D3FEND Techniques:
To specifically counter the 'FortiBleed' campaign, organizations must immediately deploy phishing-resistant multi-factor authentication across all FortiGate administrative interfaces and SSL-VPN portals. This is not just a recommendation but a critical, urgent requirement. Given that attackers are using credential stuffing and brute-force, MFA acts as a direct blocking mechanism. Prioritize deployment for all accounts with administrative privileges and any user accounts that provide broad network access via VPN. Use hardware tokens or authenticator apps (FIDO2/WebAuthn) over less secure methods like SMS. This directly hardens the authentication process for sslvpnd and other Fortinet daemons targeted by the attackers, rendering stolen or cracked passwords insufficient for gaining access.
In the context of the FortiBleed threat, Network Isolation should be applied to restrict all access to the FortiGate management plane. The administrative interface should never be exposed to the public internet. Create strict firewall rules that only allow access from a dedicated, hardened management VLAN or a small, static set of IP addresses corresponding to security team jump boxes. This significantly reduces the attack surface available to the initial access brokers scanning the internet for vulnerable Fortinet devices. By preventing the attackers from even reaching the login page, their brute-force and credential stuffing tools are rendered ineffective. This is a fundamental hardening practice that provides a powerful layer of defense before authentication even occurs.
The FBI and U.S. Secret Service issue a joint advisory (JCSA-20261006-01) on the 'FortiBleed' campaign.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.