FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

The Ongoing FortiBleed Attacks: Locking Out VPN Administrators and Opening Up Ransomware Opportunities

A concerning trend has emerged in the world of cybersecurity, with the FBI warning that FortiBleed attacks are still ongoing. These attacks target exposed Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators and creating an opening for ransomware groups to strike. The scope of these attacks is staggering, with over 86,644 devices compromised so far.

The attackers gain access to these endpoints by using previously leaked credentials or those obtained through various malicious means such as infostealer logs, credential stuffing, and password spraying attacks. Once inside, they extract additional authentication data from the compromised devices, which is then used in a distributed GPU cluster running Hashcat and Hashtopolis to crack offline the stolen password hashes. The FBI has confirmed that this attack chain has been observed as an initial entry point for ransomware affiliates.

The FortiBleed attacks are a direct result of a massive Fortinet credentials leak discovered in June, which revealed over 73,932 firewall URLs across 194 countries. The data showed a large-scale credential-harvesting operation, although it was unclear at the time what method was used to obtain the configuration data. In July, SOCRadar linked FortiBleed to the INC and Lynx ransomware operations after gaining access to their negotiation panels on a server used in the campaign.

The FBI warns that in some cases, the threat actor creates administrator accounts and uses their privileges to delete existing admin accounts or change their passwords, denying victims access to their devices. The attacker then establishes persistence and tries to move laterally in the environment. Details about the operation became known after the attacker accidentally exposed their backend server, revealing a directory with tooling and datasets.

The exposure showed the use of automated scripts to scan exposed FortiGate SSL VPN portals, a distributed GPU password-cracking setup, and scripts to validate credentials, filter out honeypots, identify organizations, and prioritize targets by revenue and network structure. The revelation also revealed working VPN configurations and target lists, indicating that the operator was packaging compromised access for sale.

The FBI warns that remediation may require more than patching and resetting Fortinet passwords. They recommend restricting external access, terminating all active VPN sessions, enforcing MFA, and reviewing logs for unauthorized changes and suspicious activity. It’s also recommended to enforce PBKDF2 for administrator password storage, which is much stronger than legacy SHA-256 hashes that attackers can practically crack offline.

In light of these ongoing attacks, it’s essential for organizations using FortiGate firewalls to review their security posture and take immediate action to prevent further exploitation. This includes regularly reviewing logs for suspicious activity, enforcing strong passwords, and limiting external access to sensitive systems. By taking proactive steps to secure their infrastructure, organizations can reduce the risk of falling victim to these targeted attacks and minimize the potential damage from ransomware groups.


Source: Bleeping Computer — 2026-10-07