FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

The ongoing FortiBleed attacks have left thousands of Fortinet FortiGate firewalls and SSL VPN gateways vulnerable to hackers, who are using compromised credentials to lock out legitimate administrators. The Federal Bureau of Investigation (FBI) has issued a warning about the attacks, which have been linked to ransomware operations and have affected over 86,644 devices across 194 countries.

At the heart of the issue is a massive credential leak discovered in June, known as FortiBleed. This incident exposed a server containing usernames and plaintext passwords associated with 73,932 firewall URLs. Hackers were able to use these leaked credentials, along with other techniques such as logins obtained from infostealer logs, credential stuffing, and password spraying attacks, to gain access to exposed endpoints.

Once inside, the attackers extract additional authentication data from compromised devices and use a distributed GPU cluster running Hashcat and Hashtopolis to crack offline the stolen password hashes. This has allowed them to gain administrator-level access to the affected systems, which they then use to establish persistence and move laterally in the environment.

The FBI has noted that in some cases, the attackers create administrator accounts and use their privileges to delete existing admin accounts or change their passwords, effectively locking out legitimate administrators. The agency warns that remediation may require more than just patching and resetting Fortinet passwords, suggesting that restricting external access, terminating all active VPN sessions, enforcing multi-factor authentication (MFA), and reviewing logs for unauthorized changes and suspicious activity are also necessary.

The exposure of the attackers’ backend server has provided a rare glimpse into their operations. Automated scripts were used to scan exposed FortiGate SSL VPN portals, while a distributed GPU password-cracking setup was employed to crack offline the stolen password hashes. Scripts were also used to validate credentials, filter out honeypots, identify organizations, and prioritize targets by revenue and network structure.

What’s particularly concerning is that the attackers have been packaging compromised access for sale, indicating a potentially large-scale operation. The FBI warns that Fortinet administrators must take immediate action to secure their systems, including enforcing PBKDF2 for administrator password storage, which is much stronger than legacy SHA-256 hashes that attackers can practically crack offline.

In light of these findings, it’s essential for organizations using Fortinet devices to review their security posture and implement additional measures to prevent similar attacks. This includes regularly updating software and firmware, monitoring logs for suspicious activity, and enforcing MFA to prevent unauthorized access. By taking proactive steps, administrators can reduce the risk of being locked out of their own systems by these ruthless attackers.


Source: Bleeping Computer — 2026-10-07