(TLP:CLEAR) FBI and Secret Service Warn FortiBleed Credential Campaign Remains Active
Created: Thursday, October 8, 2026 - 15:07
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
Summary: The FBI and U.S. Secret Service (USSS) have released a joint cybersecurity advisory warning that FortiBleed, a credential-harvesting campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, remains active. The operation exploits reused or leaked credentials and legacy SHA-256 password storage to harvest and crack authentication data at scale. First documented in June 2026, it is estimated to have collected more than 86,644 working device credentials across 194 countries, and attackers continue to scan exposed Fortinet devices using credentials they already hold. See WaterISAC’s original updates regarding this campaign here.
The advisory describes a mature, multi-stage operation: scanning for exposed SSL VPN portals, gaining access through credential stuffing and password spraying, cracking harvested hashes on a GPU cluster, creating new administrative accounts for persistence, and then selling access to downstream actors. Access brokered through FortiBleed has been tied to INC/Lynx and Payload ransomware deployments. Notably, some victims have been locked out of their own Fortinet devices after threat actors changed or deleted legitimate administrator accounts, which can force a full factory reset and rebuild before recovery.
Analyst Note: Internet-exposed firewalls and VPN gateways are exactly the kind of remote-access chokepoint that many water and wastewater utilities depend on, and they are a recurring entry point in attacks on the sector. The lockout behavior raises the stakes: this is not a quiet credential leak that patching resolves, but an active access operation where valid stolen credentials remain useful months later. A utility that only applies updates, without rotating credentials and hunting for unauthorized accounts, may still be exposed.
WaterISAC encourages members running Fortinet appliances to treat possible exposure as a compromise. Priorities include:
- Remove internet-facing management interfaces, or restrict them to trusted hosts.
- Terminate active VPN and admin sessions, then reset all Fortinet credentials and enforce phishing-resistant MFA.
- Review firewall, VPN, and domain controller logs and audit all accounts and API keys for unauthorized additions.
Members can review the advisory’s indicators of compromise (IOCs), including the listed IP addresses and compromised account names, and report any matches to WaterISAC and the FBI.
Original Source: https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html
Additional Reading:
- Analysis of Reported Credential Compromise of FortiGate Devices (Fortinet PSIRT)
- Enforcing PBKDF2 as Hash Function for Administrator Accounts in FortiOS v7.2.11 and Later (Fortinet)
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 10.2, 12
