FBI, Secret Service: FortiBleed Attackers Lock Victims Out of Fortinet

An FBI and Secret Service advisory says a Russian initial access broker is using stolen credentials to lock organizations out of Fortinet FortiGate devices.
Table of Contents
    Add a header to begin generating the table of contents

    The FBI and the US Secret Service have warned that the FortiBleed campaign against Fortinet devices is still active and that attackers are now locking victims out of their own equipment by changing passwords and deleting accounts.

    The joint advisory is dated October 6. It attributes the campaign to a Russian initial access broker and says it has run since June 2026.

    Attackers Change Passwords and Delete Accounts After Gaining Access

    According to the advisory, the actors lock organizations out of Fortinet devices by changing passwords and deleting accounts, then attempt lateral movement into the victim’s network. Losing administrative control of a firewall or VPN appliance removes the owner’s ability to manage a device that sits at the network perimeter.

    The campaign targets Fortinet FortiGate firewalls and SSL VPN appliances. About 86,644 devices across 194 countries are involved, according to the reporting on the advisory. Coverage describes tens of thousands of devices as compromised.

    No CVE Is Involved

    The advisory cites no CVE. Access in this campaign is driven by credentials rather than by a software vulnerability, so installing firmware updates does not by itself close the route the attackers use.

    How the Broker Obtains Access

    The advisory lists several methods the actors use to get in:

    • Previously compromised credentials.
    • Brute force attacks.
    • Infostealer logs and old credential dumps.
    • Offline hash cracking.
    • Scanning for exposed SSL VPN portals.

    Together these point to an approach built on volume and reuse. Credentials that leaked through earlier incidents or infostealer infections are tried against internet-facing VPN portals that the actors have found by scanning.

    The Role of an Initial Access Broker

    The advisory attributes the activity to a Russian initial access broker. Brokers specialize in gaining entry to networks and are typically associated with passing that access to other criminals. The advisory describes the lockouts and attempted lateral movement as the actors’ activity, and it does not identify who ultimately buys or uses the access.

    Guidance From the FBI and Secret Service

    The agencies recommend that organizations take the following steps:

    • Reset all Fortinet VPN and administrator passwords.
    • Use phishing-resistant multi-factor authentication.
    • Review users, configurations and API keys on the devices.
    • Identify compromised hosts.

    The recommendation to review configurations and API keys reflects that an attacker with administrative access can change settings or create new credentials that persist after a password reset.

    Timeline of the Campaign

    The campaign began in June 2026. The FBI and Secret Service issued their advisory on October 6, and press coverage of the lockouts followed on October 7 and 8. The advisory’s statement that the campaign remains active means the agencies expect further attempts against devices that still rely on the old credentials.

    What the Lockouts Mean for Victims

    For victims, the damage goes beyond unauthorized access. An organization that cannot log into its own perimeter device may be unable to inspect traffic, alter firewall rules or investigate how the attackers arrived. Because attackers also attempt lateral movement, the compromise can reach systems behind the device.

    The campaign spans about 86,644 devices. The advisory does not name victims or say how many organizations have been locked out.

    The advisory’s list of methods shows that no single weakness is required. Where one route fails, the actors can fall back on another, whether that is a password recovered from an old dump or one cracked offline from stolen hashes. The advisory states that the campaign remains active as of its October 6 date, and it specifies the targets as FortiGate firewalls and SSL VPN appliances.

    Organizations with Fortinet SSL VPN portals exposed to the internet are the group the advisory addresses, and its first instruction for them is to reset every password.

    Related Posts