FortiBleed Attackers Lock Out Organizations from Fortinet Devices Worldwide
A highly sophisticated cyber attack campaign, known as FortiBleed, has been making headlines for months, targeting organizations with Fortinet’s firewalls and VPN appliances. The attackers have been using compromised credentials and brute-force techniques to gain access to vulnerable devices, but the latest twist is that they’re now locking victims out of their own systems.
The campaign started in June and has already affected over 86,000 Fortinet devices in 190 countries. Initial analysis revealed that the attackers were using previously compromised credentials and brute-force techniques to take control of poorly protected devices. However, it’s the latest phase of the attack that poses a significant threat to organizations worldwide. According to SOCRadar, which has confirmed the compromise of approximately 86,644 devices in 194 countries, the attackers are now locking organizations out of their Fortinet appliances by changing passwords and deleting accounts.
The FBI and US Secret Service (USSS) have released a joint advisory warning that the hackers have been scanning for exposed SSL VPN portals, harvesting credentials from infostealer logs and previous dumps, cracking hashed credentials offline, mapping the attack surface to evade honeypots, using verified credentials to compromise devices, and selling working VPN configs and target lists to other threat actors.
The attackers’ goal is clear: they want to maintain control of the compromised systems while preventing organizations from accessing their own devices. This can have severe consequences for businesses, including loss of productivity, revenue, and sensitive data. It’s essential that affected organizations take immediate action to identify the compromised hosts, scope the intrusion, evict the attackers, harden protections to prevent additional threat actor activity, and report the intrusions.
To reduce their attack surface, organizations should restrict management access, reset all Fortinet VPN and administrative passwords, implement phishing-resistant multifactor authentication (MFA), review firewall and VPN users and configurations, review and validate API keys, review logs for suspicious activity, and ensure credentials are stored securely. It’s also crucial to regularly update and patch Fortinet devices, as well as conduct thorough risk assessments to identify vulnerabilities.
In the face of this sophisticated threat, organizations must remain vigilant and proactive in their security efforts. By understanding the tactics used by the attackers and taking concrete steps to mitigate their impact, businesses can minimize the damage caused by the FortiBleed campaign.
Source: SecurityWeek — 2026-10-08