The FBI and the U.S. Secret Service have warned that the FortiBleed campaign is still active and continues to target internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The campaign focuses on stealing valid credentials that can give attackers access to networks and security devices. According to the agencies, attackers are continuing to scan internet-exposed Fortinet devices using credentials that were already obtained or compromised. The warning shows that organizations using Fortinet equipment remain at risk if exposed devices and credentials have not been properly secured.
FortiBleed was first reported in June 2026 after researchers identified a large-scale campaign targeting Fortinet firewalls around the world. By June 19, the operation had collected more than 86,644 working device credentials across 194 countries. The campaign has been linked to Russian-speaking threat actors and involves credentials obtained through previous data leaks and infostealer logs. Fortinet has said the activity involves the reuse of previously compromised credentials and brute-force attacks against devices with weak password protection and without multi-factor authentication, rather than a new Fortinet software vulnerability.
The attack follows several stages to gain and expand access. Attackers first search the internet for exposed Fortinet portals and then use credential stuffing and password spraying to gain access to vulnerable devices. Once inside, they can deploy a tool known as FortigateSniffer, which passively monitors authentication traffic across 24 protocols and collects credentials and password hashes. The stolen hashes are then sent to GPU-powered cracking systems using tools such as Hashmat and Hashtopolis, allowing attackers to recover passwords that can be used for further access.
After obtaining working credentials, attackers can move deeper into affected networks and search for valuable accounts and systems. The FBI and Secret Service said the stolen access has been used for lateral movement, Active Directory enumeration, Kerberos validation and SMB authentication. Attackers have also created new administrative accounts on compromised firewalls to maintain access even after organizations attempt to secure existing accounts. In some cases, attackers may delete or change the passwords of original accounts, potentially locking organizations out of their own Fortinet devices while the attackers continue moving through the network.
The campaign has already led to warnings from cybersecurity authorities asking organizations to take immediate defensive measures. Recommended actions include enabling phishing-resistant authentication, terminating active SSL VPN and administrative sessions, resetting Fortinet VPN and administrative passwords and using PBKDF2 for administrator credential storage. Organizations are also advised to review firewall and authentication logs carefully for unusual activity, new administrator accounts or other signs that an attacker may already have gained access. Fortinet has separately urged customers to complete the remediation steps associated with the earlier credential-compromise advisories and strengthen password and MFA protections.
If an organization believes its Fortinet device may have been compromised, security teams should isolate the affected device and preserve relevant logs and other evidence before taking further response actions. The FBI and Secret Service have advised affected organizations to report suspected incidents and apply the recommended countermeasures to limit additional damage. The main concern is not simply the number of exposed credentials, but what attackers can do after those credentials are successfully used. With more than 86,644 devices linked to the campaign across 194 countries, FortiBleed remains an important warning for organizations to secure internet-facing Fortinet systems, reset potentially exposed credentials and strengthen authentication before attackers can use stolen access to move further into their networks.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news