What the FBI and Secret Service said
The FBI and U.S. Secret Service published a joint advisory on October 6, 2026, titled "FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts." It describes FortiBleed as an active, global credential-compromise campaign aimed at internet-facing FortiGate firewalls and SSL VPN gateways. The agencies say the attack chain has been seen as an initial entry point for ransomware affiliates.
The headline figure is SOCRadar's count of at least 86,644 devices across 194 countries. That number belongs to SOCRadar. The agencies cite it. It is not a new FBI or Secret Service tally.
Not a patch-and-forget bug
Reporting on the advisory says no confirmed CVE or zero-day has been identified. The agencies say the campaign exploits reused or leaked credentials and legacy SHA-256 password storage, which lets attackers harvest and crack authentication data at scale. The alert says that once attackers gain access, they can create accounts or change passwords to lock users out, so standard password resets and patching are insufficient.
You can't close this one by installing an update and going home. If an attacker already holds a valid administrator login, a firmware patch doesn't remove it.
How the attack works
According to The Register's reading of the advisory, the criminals:
- Use credentials from earlier breaches and infostealer logs for credential stuffing and password spraying against exposed FortiGate devices.
- Extract password hashes from compromised devices.
- Crack those hashes offline on GPU-accelerated clusters.
- Create new accounts on the device that weren't there before.
- In some cases, delete existing accounts to keep owners out while they try lateral movement.
The agencies' own text says threat actors delete existing accounts in certain cases to block organizations from accessing affected devices and to maintain persistence while attempting lateral movement.
The evidence brief for this story adds some detail. The advisory reportedly reconstructs the workflow from artifacts left on the attackers' own exposed backend server. It names Hashcat and Hashtopolis as the cracking tools. It also says the attackers enumerated Active Directory accounts and sprayed passwords for further access once inside victim networks. I couldn't open the PDF directly during this check, so treat those specifics as drawn from the research notes. Search results did confirm the advisory's core claims.
Ransomware connection
The FBI warned that the attack chain has been an entry point for ransomware affiliates, including those for INC/Lynx and Payload. The Register notes that SOCRadar said in July it had seen at least 12 confirmed ransomware attacks stemming from FortiBleed. The brief says the new joint advisory doesn't repeat that number. Keep the two apart:
- Advisory: access has been supplied to ransomware affiliates.
- SOCRadar: a specific count of confirmed deployments, reported earlier.
A daily.dev summary blends these into one claim. The advisory text, as described in the research notes, does not.
There is also a figure dispute. A CyberScoop summary line mentions "over 400,000" devices, which doesn't match the 86,644 figure used by the other outlets. I couldn't reconcile it, so I'm using the SOCRadar number the agencies cite.
What defenders should do
The advisory's recommendations, as described in the reporting and research notes:
Reduce exposure
- Restrict external management with trusted hosts or a local-in policy. Ideally, remove internet-facing administration entirely.
- Terminate active administrative and VPN sessions.
Reset and strengthen credentials
- Reset Fortinet VPN and administrator passwords, especially on internet-facing systems.
- Require phishing-resistant MFA on remote-access and administrative accounts. Check that it is actually enforced on external gateways and management interfaces.
- Confirm administrator credentials use PBKDF2 and remove weaker legacy hashes. The advisory points to Fortinet guidance for FortiOS 7.2.11 and later.
- Review REST API keys, remove unknown ones, and refresh the legitimate ones.
Hunt for compromise
- Compare firewall and VPN configuration against a known-good baseline.
- Look for unfamiliar administrator accounts. The advisory lists names seen on victim systems, such as
fortiAdmin,forticloud-sync,support_fortinetandsystem_config. Treat these as leads to validate against your own records, not proof of compromise. Some organizations may use similar names legitimately. - Review firewall, VPN, authentication and domain controller logs for lateral movement and configuration changes.
- Note that SSH may have been exploited where the firewall's SSH port was open.
If you suspect compromise
- Isolate affected hosts and threat hunt to establish the timeline and which accounts are affected.
- The advisory points to CISA's Eviction Strategies Tool for planning.
Indicators come with caveats
The advisory lists IP addresses tied to brute-forcing, authentication with compromised accounts, command-and-control, proxies and Hashtopolis. According to the brief, observation dates run from June 18 through July 23, 2026. The agencies caution that the infrastructure may sit on cloud or virtualized hosting and that addresses get reassigned. Verify indicators against your own telemetry before blocking. Blindly blocking stale cloud IPs is a good way to feel productive while achieving little.
The lockout problem
Lockout turns a bad day into a worse one. If the legitimate admin accounts are deleted or their passwords changed, you may not be able to inspect the device or change its configuration normally. Plan the recovery path before you need it. That includes console or out-of-band access, current configuration backups, and a contact at your vendor or integrator.
For Windows shops, the practical point is that the firewall is the front door to Active Directory. A compromised VPN gateway gives attackers a valid foothold inside the network. That's why the advisory's advice to review domain controller logs matters as much as the firewall cleanup.
Reporting and ransom guidance
The advisory was shared publicly by FBI Las Vegas on X after the FBI Cyber Division first posted the alert. The agencies say organizations are not obliged to respond or share information. Those who do can report through the FBI's IC3 or local FBI and Secret Service field offices. The agencies don't encourage paying ransoms, because payment doesn't guarantee file recovery and can fund further crime.
Bottom line
FortiBleed isn't a patch Tuesday problem. It's a credential hygiene and exposure problem, and the federal warning confirms it is still being exploited and still feeding ransomware operations. If you run an internet-facing FortiGate, three steps matter most:
- Take management off the internet.
- Enforce phishing-resistant MFA.
- Audit your accounts, API keys and password hash settings, because a clean patch level proves nothing here.
References
- FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks The Register · 2026-10-07T10:52:09+00:00
- Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks cyberscoop.com
- FBI Warns of FortiBleed Attacks Leading to Lockouts, Ransomware - Decipher decipher.sc