Skip to content

Security6 publishersWidely confirmed2 min readPublished

FortiBleed keeps scanning exposed Fortinet firewalls as toll grows to 400,000-450,000 devices

The FBI and Secret Service warned Tuesday that FortiBleed is still scanning Fortinet firewalls and SSL VPN gateways with 86,644 stolen credentials. Patching and a password reset will not clear it.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying FortiBleed keeps scanning exposed Fortinet firewalls as toll grows to 400,000-450,000 devices
Generated illustration

What happened

  • SOCRadar and Hudson Rock first documented FortiBleed in June 2026 as a global campaign hitting thousands of Fortinet firewalls.
  • The intruders create admin accounts that were never on the device and delete the legitimate ones, locking owners out of their own firewalls.
  • Operator overlaps and brokered access sales tie FortiBleed to the INC, Lynx and Payload ransomware operations.
  • The accounts the attackers plant use names built to blend in, among them fortiAdmin, forticloud-sync and support_fortinet.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Operators have to end active SSL VPN and admin sessions, require phishing-resistant authentication, and store admin credentials with PBKDF2 rather than the legacy SHA-256 hashing the attackers crack.
  • cost A FortiGate the attacker touched cannot be recovered with a login; the FBI says to isolate it, preserve its logs and artifacts, and treat it as compromised.
  • precedent The group brokers access instead of using it, so a credential stolen now can resurface later as a ransomware intrusion run by an unrelated affiliate.

"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale," the FBI and Secret Service said. [12] The entry point is credentials, so there is no patch to wait for.

FortiBleed runs in five stages. It scans the internet for exposed Fortinet portals, breaks in with credential stuffing and password spraying built from old leak dumps and infostealer logs, and plants a Go tool the agencies call FortigateSniffer, which passively intercepts authentication traffic across 24 protocols and lifts credentials and password hashes. [6] The hashes go to a GPU cracking cluster running Hashmat and Hashtopolis, and the cracked logins drive lateral movement, Active Directory enumeration, Kerberos validation and SMB authentication. [8] In the last stage the operators pull data off network shares and keep authenticated access with stolen session cookies. [9]

The target selection is deliberate. "Cracked credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure," the agencies said. [10]

The verified count is a floor. SOCRadar chief information security officer Ensar Seker told CyberScoop that "in our later investigation, we identified more than 400,000 or 450,000 firewalls targeted by the wider operation." [17] Against the devices the firm first verified, that puts confirmed compromises at roughly one in five of the firewalls the operation went after. [22] [14] The numbers, Seker said, "show the campaign is broader and more serious than we understood at the beginning." [18]

The FBI and Secret Service are collecting indicators of compromise, including the attacker IP addresses and the usernames the operators create on breached appliances. [20]

What to watch

  • Whether Fortinet ships configuration changes or CISA issues binding guidance to disable internet-facing FortiGate management by default.
  • Whether INC, Lynx or Payload claim victims whose entry traces back to FortiBleed-harvested credentials.
  • Whether SOCRadar or the agencies publish the IP addresses and attacker-created usernames they are now collecting.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories