The U.S. Federal Bureau of Investigation (FBI) and the Secret Service have issued a warning regarding the ongoing cyber threat posed by the FortiBleed campaign. This malicious activity targets Fortinet FortiGate firewalls and SSL VPN gateways, exploiting reused or leaked credentials alongside outdated SHA-256 password storage methods. Such tactics allow cybercriminals to harvest and crack authentication data on a large scale.
Details of the FortiBleed Campaign
The FortiBleed operation, first identified by SOCRadar in June 2026, has been actively targeting thousands of Fortinet devices worldwide. The campaign, primarily attributed to Russian-speaking actors, has reportedly acquired over 86,644 device credentials across 194 countries by mid-June 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has advised Fortinet users to adopt phishing-resistant authentication, reset passwords, and monitor for unusual activity.
FortiBleed comprises five stages, beginning with reconnaissance to identify vulnerable systems. It employs credential stuffing and password spraying techniques to gain access, followed by the use of a tool named FortigateSniffer to capture authentication traffic. The stolen password hashes are processed using advanced cracking techniques, enabling further infiltration into networks through lateral movement and data exfiltration.
Impact and Persistence of Attacks
With validated credentials, attackers can deeply embed themselves within victim networks, creating new accounts and conducting enumeration to broaden their access. Commonly compromised account names include ‘adminin’, ‘fortiAdmin’, and ‘forticloud-sync’. These actions ensure attackers maintain persistent access and continue to exploit compromised systems.
The perpetrators, suspected to be initial access brokers, sell stolen data to other threat actors, possibly for ransomware deployment. Associations with INC and Lynx ransomware operations suggest such transactions. Victims may find themselves locked out of their systems if attackers modify or remove original accounts.
Preventive Measures and Recommendations
Organizations that detect potential compromises are urged to isolate affected devices and gather relevant logs and artifacts. Reporting incidents to the FBI and USSS is crucial, alongside implementing countermeasures to mitigate the threat. By enhancing security protocols and monitoring for suspicious activity, organizations can better protect themselves against ongoing cyber threats.
In conclusion, the FortiBleed campaign remains a significant security concern, necessitating proactive measures to safeguard network infrastructure. Organizations are advised to remain vigilant and responsive to emerging cybersecurity challenges.
