86,644 Firewalls in 194 Countries Breached With Stolen Passwords
The FBI and the U.S. Secret 2026-10-7 14:34:11 Author: thecyberexpress.com(查看原文) 阅读量:6 收藏

FortiBleed

The FBI and the U.S. Secret Service (USSS) have issued a joint cybersecurity advisory warning organizations about FortiBleed, an active global credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The advisory, published on October 6, 2026, cites SOCRadar data verifying more than 86,644 compromised devices across 194 countries.

According to the advisory, the campaign exploits reused or leaked credentials and legacy SHA-256 password storage, allowing threat actors to harvest and crack authentication data at scale. Attackers continue to scan exposed Fortinet firewalls using previously obtained credentials, and some affected organizations have been locked out of their own systems.

How the FortiBleed Attack Chain Works

The operation’s internal workflow came to light after the threat actors unintentionally exposed their own backend server. The open directory revealed a mature, multi-stage campaign run as an initial access broker operation.

Attackers first scanned the internet for exposed FortiGate SSL VPN portals using automated scripts. They then gathered credentials through credential stuffing and password spraying, drawing on prior Fortinet leak dumps and infostealer logs.

Password hashes taken from compromised devices were exfiltrated and fed into a GPU-accelerated cracking cluster running on rented infrastructure, where Hashcat and Hashtopolis ran distributed jobs to convert stolen data into plaintext credentials.

FortiBleed Attack Chain
Source: FBI

Cracked credentials were then validated, with scripts filtering out honeypots, mapping organizations and ranking high-value targets by revenue and network structure. Attackers created new administrative accounts on firewalls to maintain persistence, then moved into victim networks to enumerate Active Directory and identify privileged accounts. The final stage involved selling access, including working VPN configurations and target lists, to downstream threat actors.

FortiBleed Lockouts and Ransomware Links

The advisory warns that victims may lose access to their Fortinet devices if attackers delete original accounts or change their passwords. In certain cases, threat actors removed existing accounts to block organizations from their devices while attempting lateral movement. Recovery may require steps beyond standard patching and password resets.

Reporting also indicates that initial access brokers using the FortiBleed attack chain have supplied access to ransomware affiliates, currently including INC/Lynx ransomware and Payload ransomware.

FortiBleed Indicators of Compromise

The agencies released indicators of compromise (IOCs) to help defenders review their environments. IP address 45.154.12.132 was observed as a command and control server, while 154.202.59.169 and 103.27.186.156 served as proxy nodes and 45.155.250.158 functioned as a beacon relay. The address 85.11.187.8 was linked to the Hashtopolis tool. The advisory also lists 13 IP addresses observed between June 18 and July 23, 2026, conducting brute force attacks or authenticating with compromised accounts.

Account names found on victim systems include adminin, fortiAdmin, forticloud-sync, fgtsecure, adminsslvpn, itadmin and roadmin. The agencies note that IP addresses may be reassigned over time and advise organizations to vet IOCs before acting on them.

Recommended Mitigations Against FortiBleed

The FBI and USSS recommend that organizations:

  • Restrict external management through trusted hosts, a local-in policy, or by removing internet administration entirely.
  • Terminate all active admin and VPN sessions and reset all Fortinet VPN and administrative passwords.
  • Enforce phishing-resistant MFA on all remote access and administrative accounts.
  • Review firewall and VPN configurations for unrecognized accounts and unauthorized changes.
  • Check firewall, VPN, authentication and domain controller logs for unusual access.
  • Use PBKDF2 to store administrator credentials and remove weaker legacy hashes, following Fortinet guidance for FortiOS v7.2.11 and later.
  • Review all REST API keys, remove unknown ones and refresh legitimate keys.

Organizations that detect a compromise are urged to isolate affected hosts, scope the intrusion and report incidents to the FBI’s Internet Crime Complaint Center (IC3), a local FBI field office or a local USSS field office.


文章来源: https://thecyberexpress.com/fortibleed-campaign-hits-fortinet-devices/
如有侵权请联系:admin#unsafe.sh