The FBI is warning that FortiBleed attacks remain ongoing against exposed Fortinet FortiGate firewalls and SSL VPN gateways, with intruders locking legitimate administrators out of the devices they manage. Attackers reach the exposed endpoints using credentials that were previously leaked, logins pulled from infostealer logs, credential stuffing, and password spraying. Once inside, they pull additional authentication data off the compromised devices and crack the stolen password hashes offline using a distributed GPU cluster running Hashcat and Hashtopolis.
FortiBleed itself is a large Fortinet credentials leak that surfaced in June, when attackers accidentally exposed a server holding usernames and plaintext passwords tied to 73,932 firewall URLs across 194 countries. The data pointed to a broad credential-harvesting campaign, though the method used to obtain the configuration data was not clear at the time. In July, SOCRadar tied FortiBleed to the INC and Lynx ransomware operations after gaining access to both groups' negotiation panels on a server used in the campaign. By SOCRadar's most recent count, FortiBleed has compromised 86,644 devices.
According to the FBI, the threat actor in some incidents sets up administrator accounts and then uses those privileges to delete existing admin accounts or change their passwords, cutting victims off from their own devices. The attacker then works to establish persistence and attempts to move laterally through the environment.
Details of the operation emerged after the attacker inadvertently exposed a backend server, revealing a directory containing tooling and datasets. Those files showed automated scripts scanning exposed FortiGate SSL VPN portals, a distributed GPU password-cracking setup, and scripts used to validate credentials, filter out honeypots, identify organizations, and rank targets by revenue and network structure. The exposure also revealed working VPN configurations and target lists, indicating the operator was packaging compromised access for sale.
The FBI cautioned that remediation may go beyond patching and resetting Fortinet passwords. The bureau suggested restricting external access, terminating all active VPN sessions, enforcing MFA, and reviewing logs for unauthorized changes and suspicious activity. It also recommended enforcing PBKDF2 for administrator password storage, which is considerably stronger than the legacy SHA-256 hashes that attackers can practically crack offline.
More cybersecurity news from TechManNews.








