Cybersecurity

FortiBleed Campaign Isolates Organizations from Fortinet Devices After Taking Them Over

The FortiBleed campaign continues targeting exposed FortiGate devices, firewalls, and SSL VPN gateways, with approximately 86,644 devices in 194 countries confirmed compromised. The FBI and USSS warn that attackers are changing passwords and deleting accounts to prevent organizations from accessing their devices.

2026-10-08
3 min read
1 views
certi.news
FortiBleed Campaign Isolates Organizations from Fortinet Devices After Taking Them Over

The FortiBleed campaign to steal credentials and sell initial access continues targeting internet-connected Fortinet devices, while attackers have begun isolating some organizations from their devices by changing passwords and deleting original accounts. The targeting includes FortiGate firewalls and SSL VPN devices accessible from the internet.

The campaign began in June, and a Fortinet analysis revealed that attackers exploited compromised credentials and brute-force guessing techniques to take control of poorly protected devices. Within one week, the attacks affected more than 86,000 devices in 190 countries, and the campaign was attributed to a Russian initial access broker.

Scope of the Confirmed Breach

SOCRadar confirmed the compromise of approximately 86,644 devices in 194 countries. The company notes that the figure represents devices proven to have been compromised, rather than an estimate of the number of vulnerable devices; devices compromised months ago also remain listed in the attackers’ verified inventory.

SOCRadar says the attackers search for accessible firewalls and use stolen credentials to take control of them. Observed methods include scanning exposed SSL VPN gateways, extracting login data from infostealer logs and previous leaks, cracking passwords offline, and mapping the attack surface to avoid honeypot systems.

What Is Changing in Practice?

In a joint warning issued this week, the United States Federal Bureau of Investigation (FBI) and the United States Secret Service (USSS) warned that attackers may change or delete the original account passwords, preventing information technology teams from accessing affected Fortinet devices. This step may be used to maintain persistence within the system and pave the way for lateral movement in the compromised environment.

The sale of working VPN configurations and target lists to other threat actors has also been observed, turning the initial compromise into an asset that can be traded among multiple attackers.

Recommended Containment Measures

  • Identify compromised host devices and assess the scope of the intrusion before restoring access.
  • Remove the attackers from the environment and strengthen protections to prevent further activity.
  • Restrict administrative access to the devices and reset all VPN and Fortinet administrative account passwords.
  • Implement phishing-resistant multifactor authentication.
  • Review firewall and VPN users and settings, and verify API keys.
  • Inspect logs for suspicious activity and store credentials securely.

Why Does This Matter?

The risk is not limited to losing access to a security device; control of a firewall or VPN gateway gives an attacker a foothold at the network perimeter and may enable movement within the environment or the resale of access. The warning demonstrates that changing accounts and passwords is part of post-compromise persistence, so restoring a single administrative account is not enough before examining the device and the broader scope of the intrusion. Details of each incident, including the extent of lateral movement, still require a separate investigation according to the warning.

News source
c
Author

certi.news

In the same category

You may also like

View all news