Quick Takeaways
- The active FortiBleed campaign exploits compromised credentials and legacy hashing to target internet-facing Fortinet FortiGate firewalls and SSL VPNs globally.
- The attack involves reconnaissance, credential stuffing, credential interception with a custom tool, and credential cracking to facilitate lateral movement and data exfiltration.
- Threat actors establish persistence by creating or deleting accounts, with suspected links to ransomware groups like INC and Lynx.
- Organizations are urged to enhance authentication, review logs, and report incidents swiftly to prevent further compromise and mitigate risks.
FBI Warns of Ongoing Threat from FortiBleed Campaign
The FBI and the Secret Service issued a warning on Tuesday about a persistent cyber threat known as the FortiBleed campaign. This campaign targets Fortinet firewalls and SSL VPN gateways that face the internet. The threat actors exploit weak or reused passwords, along with old password storage methods, to access these devices. They continue scanning the internet for vulnerable FortiGate firewalls using already stolen credentials. As a result, over 86,644 device credentials from 194 countries were collected by the attackers as of June 2026. This situation urges organizations to reinforce their security measures, including enabling stronger authentication processes and reviewing logs for suspicious activity. Such actions are essential because this campaign is capable of bypassing traditional defenses, thus increasing the risk of data breaches and unauthorized access.
Technical Tactics and Broader Implications
The attackers behind FortiBleed follow a five-stage plan to compromise systems. They start by identifying exposed portals on networks. Next, they use information from previous leaks to attempt access via credential stuffing and password spraying techniques. Once inside, they deploy a tool that passively intercepts traffic and harvests login information across nearly two dozen protocols. The stolen data is then cracked using GPU-powered tools, allowing hackers to move laterally within networks, conduct detailed reconnaissance, and ultimately exfiltrate sensitive files. Furthermore, the campaign creates new admin accounts or deletes existing ones to maintain persistence. This method shows that these hackers may serve as intermediaries, selling access to other cybercriminal groups like those behind ransomware. Such activities highlight the importance of proactive security practices, especially for organizations relying on Fortinet devices, to prevent potential devastating breaches.
Stay Ahead with the Latest Tech Trends
Explore the future of technology with our detailed insights on Artificial Intelligence.
Access comprehensive resources on technology by visiting Wikipedia.
DataProtection-V1
