FortiBleed Is Still Active, and a Mere Password Reset Won't Evict It
7:47
Thu | Oct 8, 2026 | 11:01 AM PDT

Four months after FortiBleed first surfaced, the U.S. Secret Service and FBI say the campaign is still running, and some victims are now locked out of their own firewalls.

The agencies released a joint Cybersecurity Advisory, titled "FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts." Its headline number—more than 86,644 compromised Fortinet devices across 194 countries—is SOCRadar's verification, which the agencies cite rather than tally themselves. That count comes from SOCRadar's June reporting, so treat it as a snapshot and not a live census.

The IP addresses listed in the advisory were active between June 18 and July 23, 2026. The more urgent finding is that attackers are still scanning exposed Fortinet firewalls with credentials they harvested earlier.

An operation that exposed itself

Most of what defenders know about FortiBleed's internals comes from the attackers' own mistake. The workflow became visible when the operators accidentally left their backend server exposed, and the open directory showed a mature, multi-stage pipeline.

The pipeline begins with automated scanning for internet-facing FortiGate SSL VPN portals. The operators then run credential stuffing and password spraying using earlier Fortinet leak dumps and infostealer logs. Password hashes extracted from compromised devices go to a GPU cluster the attackers rent, where Hashcat and Hashtopolis distribute the offline cracking jobs. The operators run it like a business. Their scripts screen out honeypots, map each victim's organization, and rank targets by revenue and network structure before anyone logs in.

[RELATED: Why the FortiBleed Campaign Is So Much Worse than a Standard Leak]

There is no patch for this

FortiBleed is not a CVE, and that is where most of the confusion starts. In June, Fortinet's PSIRT tied the campaign to credentials reused from earlier incidents involving CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719, combined with brute-force attempts against devices that had weak passwords and no MFA.

The offline cracking works because of an upgrade quirk. Fortinet moved administrator password storage to PBKDF2 in FortiOS 7.2.11, 7.4.8, and 7.6.1. Passwords carried over from earlier versions, however, stay stored as legacy SHA-256 hashes until each administrator logs in again. According to Fortinet, the old SHA-256 hash is also kept in a hidden "old-password" setting for backward compatibility. Admins can't see that setting in the firewall interface, but it shows up in a super_admin configuration backup. As a result, a device on current firmware can still hold credentials a GPU rig can crack.

Phil Wylie, Sr. Consultant and Evangelist at Suzu Labs, argues that this gap means patching alone won't fix things. "If attackers have valid credentials or have already created new administrative accounts, applying an update and changing a password may not remove them from the environment," Wylie said.

Lockouts and look-alike admins

What's new in this advisory is the destructive behavior. The agencies say affected organizations can find themselves locked out when attackers disable accounts or change passwords, which means recovery takes more than routine patching and password resets.

The intruders also set up persistence. On first access, they create administrator accounts that weren't there before. In some cases, they delete the legitimate accounts, both to keep owners out and to stay in place while they try to move laterally. The advisory lists the account names investigators found, and many are designed to look routine at a glance: names like "forticloud-sync," "support_fortinet," and "IT_Manager." The agencies also note that attackers may have come in over SSH where that port was open on the firewall.

Once inside, the operators enumerate Active Directory and spray passwords to find privileged accounts. When a firewall compromise reaches AD credentials, it is no longer a firewall incident. Wylie's guidance reflects that: treat any exposed device as possibly already compromised, and if privileged credentials were reachable from it, treat those as exposed too.

Access as a product

The business model matters as much as the technique. The operation ends by packaging working VPN configurations and target lists for sale to downstream buyers. According to the agencies, initial access brokers using the FortiBleed chain have passed access to ransomware affiliates, currently including INC/Lynx and Payload. SOCRadar separately reported in July that it had tracked at least 12 confirmed ransomware attacks traced back to FortiBleed.

"The people gaining access don't necessarily have to be the ones deploying ransomware," Wylie noted. "Initial access itself has value."

For John Strand, owner of Black Hills Information Security, that resale model is the core of the threat. "It's basically malicious hacking as a service," he said. In his view, the risk looks less like a ransomware smash-and-grab and more like an advanced persistent threat, even though the operators behind it are brokers selling access for profit.

"I'm not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence. I'm terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access," Strand concluded.

Ransomware at least announces itself. An access broker makes money by staying hidden, and so does whoever buys from them.

What to do now

The advisory's incident response steps are clear: identify the compromised hosts and isolate them, hunt to determine the scope of the intrusion, report to the FBI and USSS, and then evict. One detail is easy to miss. The agencies say to start eviction countermeasures only after collecting enough hunting data to choose them well, and they point to CISA's Eviction Strategies Tool for building the plan. If you reset everything first, you may wipe out the evidence of how far the intruders got.

For hardening, the agencies lay out management access in tiers: restricting it to trusted hosts is good, a local-in policy is better, and removing internet administration altogether is best. They also call for terminating all admin and VPN sessions, resetting every Fortinet VPN and administrative password, and requiring phishing-resistant MFA on all remote access and administrative accounts. A one-time code alone won't meet that bar.

Validate configurations against a known-good baseline and look specifically for unfamiliar accounts. Review firewall, VPN, authentication, and domain controller logs for lateral movement. Confirm that admin credentials are stored with PBKDF2 and that the legacy hashes are gone. On FortiOS 7.2.x and 7.4.x, enabling "login-lockout-upon-weaker-encryption" in the system password policy clears the SHA-256 hashes left in old-password.

One more item belongs on the checklist: API keys. The advisory recommends reviewing every REST API key on FortiGate devices, removing any you don't recognize, and refreshing the legitimate ones so attackers can't use a forgotten automation key to get back in.

The agencies say reporting is voluntary, and they advise against paying ransoms.

FortiBleed isn't a new bug. It's what happens when exposed interfaces, weak hashes, and reused credentials pile up over time. Fixing it means confirming who has access to the device today, not just updating the software.

Comments