More than 86,000 internet-facing Fortinet FortiGate firewalls and virtual private network (VPN) gateways have been compromised as part of an ongoing campaign tracked as FortiBleed, according to the FBI and Secret Service. The agencies released an advisory on Tuesday warning organizations that the credential stealing attacks on Fortinet devices have continued for months across 194 countries. The campaign exploits reused or leaked credentials, allowing hackers to “harvest and crack authentication data at scale.” “Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials,” the federal agencies explained. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets. In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.” The advisory says initial access brokers are also taking part in the campaign and offering their access to ransomware affiliates tied to the INC/Lynx ransomware and Payload ransomware. The FBI and Secret Service noted that the credential-harvesting operation became known to cybersecurity firms and law enforcement after hackers exposed their own backend server, making their internal workflow visible. “The recovered tooling and datasets provide a rare, end-to-end view of how the operators identified targets, validated stolen credentials, and expanded access inside victim networks,” the agencies said. The attackers scanned the internet for exposed FortiGate SSL VPN portals, used automated scripts to identify reachable devices and collected large volumes of credentials and authentication artifacts using credential stuffing and password spraying attacks. Stolen credentials were sorted, validated and organized based on a victim organization’s revenue or network structure. New accounts were created on firewall devices, allowing them to maintain access. Hackers either sold their access to others or used it themselves. The FBI and Secret Service said organizations should review all of their Fortinet accounts and verify their legitimacy. Cybersecurity experts have warned for months about the FortiBleed campaign. SOCRadar published a lengthy study in July detailing how affiliates of the INC and Lynx groups were taking part in the campaign. An internal tracking file found more than 20 affiliates in defined roles scanning thousands of FortiGate portals across more than 150 countries. At least 12 organizations were breached and encrypted with ransomware. The group also spent heavily on artificial intelligence tools that helped them get past model safety controls and more. The Cybersecurity and Infrastructure Security Agency (CISA) released its own warning about the campaign three months ago alongside officials in the U.K. Russian hackers allegedly used the campaign to break into email accounts of U.K. government officials. The FBI and Secret Service urged organizations to restrict external management of devices or remove internet administration altogether. Credentials should be reset and all admin VPN sessions should be terminated. Staying power
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.