FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
The FBI and US Secret Service have confirmed ongoing attacks using credentials stolen in the FortiBleed campaign, affecting over 86,644 devices across 194 countries. Criminals are locking organisations out of their Fortinet firewalls by deleting or changing legitimate passwords whilst creating new admin accounts to maintain persistence and move through networks. This campaign represents a significant threat to critical infrastructure worldwide.
The attackers exploit internet-facing FortiGate firewalls and SSL VPN gateways using stolen credentials from earlier breaches and infostealer logs, then crack password hashes offline using GPU-accelerated clusters. The campaign has been linked to multiple ransomware groups including INC/Lynx and Payload, with initial access brokers supplying compromised network access to ransomware affiliates and at least 12 confirmed ransomware attacks recorded by July.
- Over 86,644 FortiBleed-compromised devices found; criminals locking organisations out of firewalls.
- Threat actors use stolen credentials and crack passwords offline with GPU clusters.
- Ransomware groups leveraging FortiBleed access; at least 12 confirmed attacks by July.
New here? Start with this
Fortinet makes firewalls – hardware devices that protect computer networks from cyber attacks. FortiBleed is the name given to a campaign targeting these firewalls, in which criminals use stolen usernames and passwords to break in. Once inside, they delete or change the legitimate passwords that the organisation's own staff use, effectively locking them out of their own equipment.
The attackers then create new admin accounts that only they know about, giving them a permanent way back into the network even if the original password breach is discovered and fixed. From this position, they can explore the network to find valuable systems and sensitive data, or provide access to criminal partners who specialise in ransomware attacks that encrypt data and demand payment to unlock it.
The campaign has affected over 86,000 devices across nearly 200 countries, with victims ranging from businesses to organisations managing critical infrastructure like power grids and hospitals. Security agencies worldwide have linked the attacks to multiple ransomware criminal groups who work together – some specialise in initial break-ins whilst others deploy the ransomware that encrypts organisations' data.