FortiBleed Turns Stolen Fortinet Credentials Into Persistent Network Access

U.S. authorities warn FortiBleed remains active against exposed FortiGate firewalls and SSL VPNs, using stolen credentials for persistent network access.

FortiBleed Turns Stolen Fortinet Credentials Into Persistent Network Access
Data Breaches

Illustrative image generated with AI

U.S. authorities are warning organizations that the FortiBleed credential-harvesting campaign remains active against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.

According to reporting on the FBI and U.S. Secret Service warning, operators continue to scan exposed Fortinet systems using credentials stolen during earlier compromises. Successful access can provide a route into internal networks, where attackers may search for privileged accounts, collect additional credentials and steal data.

The warning was issued on a Tuesday, but the available reporting does not provide its calendar date. FortiBleed was first documented by SOCRadar in Hudson Rock in June 2026.

This is not described as a newly disclosed software vulnerability. The reported operation relies heavily on leaked, reused and intercepted credentials, combined with password cracking and techniques for preserving authenticated access.

The campaign targets exposed FortiGate and SSL VPN systems

The affected surface consists of Fortinet FortiGate firewalls and SSL VPN gateways reachable from the internet. The reporting does not identify specific product versions or associate the activity with a CVE.

FortiBleed reportedly begins by locating exposed Fortinet portals. Attackers then attempt access through credential stuffing and password spraying, using material drawn from previous credential leaks and infostealer logs.

The FBI and USSS said the operation also takes advantage of reused or disclosed passwords and legacy SHA-256 password storage. Once an authentication attempt succeeds, the firewall or VPN gateway can become an entry point for broader network activity.

As of June 19, 2026, the operation was estimated to have collected more than 86,644 working device credentials across 194 countries. That figure represents credentials, not affected people. It also should not be treated automatically as a count of distinct devices, because one system may contain multiple valid accounts.

The source describes FortiBleed as a global, Russian-speaking operation that has targeted thousands of Fortinet firewalls. Those descriptions and the scale estimate come from the cited reporting and have not been independently confirmed here.

FortigateSniffer feeds a GPU-backed cracking pipeline

The reported workflow has five connected stages: reconnaissance, initial access, credential interception, password cracking, and persistence with data theft.

After identifying and accessing an exposed Fortinet system, the operators deploy FortigateSniffer, a Go-based collection utility. The tool reportedly observes authentication traffic passively across 24 protocols, capturing both plaintext credentials and password hashes where available.

Collected hashes are then sent to a GPU-accelerated cracking environment built around Hashmat and Hashtopolis. The operators reportedly sort, enrich and validate the recovered credentials instead of treating the collected material as an undifferentiated password dump.

Scripts are also said to filter out honeypots, map organizations and rank possible victims according to factors including revenue and network structure. These steps indicate a selection process intended to concentrate effort on useful access.

Recovered credentials can support several follow-on actions:

  • Active Directory enumeration;
  • Kerberos validation;
  • SMB authentication;
  • additional password spraying;
  • discovery of privileged accounts;
  • lateral movement into connected systems.

The stages should not be treated as proof that every identified organization experienced the complete chain. Scanning, successful authentication, credential collection and internal movement represent different levels of access and impact.

New accounts and session cookies help preserve control

Once inside an environment, the operators reportedly create new administrative accounts on Fortinet devices. They may also retain authenticated access through stolen session cookies, reducing their dependence on repeatedly supplying a password.

The FBI and USSS warned that attackers can change or delete existing passwords, potentially locking legitimate administrators out of their own Fortinet appliances. In some reported cases, operators deleted existing accounts while adding replacements under their control.

This behavior serves two practical purposes. It can obstruct incident response at the device level, while also preserving a foothold as attackers move through the surrounding network.

The campaign has additionally been associated with the theft of sensitive data from network shares. Compromise of the perimeter appliance therefore does not define the full extent of possible exposure. Organizations must determine whether the attacker used that access to reach directory services, file servers or other internal resources.

The reporting assesses that the operator may function as an initial access broker, preparing and selling compromised access to other criminals. It also cites overlaps connecting FortiBleed with the INC and Lynx ransomware operations.

That connection is an indicator of possible downstream use, not proof that ransomware was deployed in every compromised network. The initial-access-broker role likewise remains an assessment rather than an independently established fact for all observed activity.

Administrators should hunt for suspicious Fortinet accounts

Account review offers one immediate detection opportunity. The following names were reported as commonly found on compromised devices:

adminin, fortiAdmin, forticloud-sync, admin, fgtsecure, pakedge, forticloud-tech, districtadmin, system_config, gttadmin, roadmin, itadmin, Technical_support, adminsslvpn, IT_Manager, my_admin, support_fortinet, fgtsec, forti_support2.

A matching name is not, by itself, conclusive evidence of intrusion. Several are generic enough to require validation against account-creation records, approved administrator inventories, authentication history and configuration changes.

Defenders should examine Fortinet logs for unexpected administrative logins, newly created or modified accounts, password resets and unexplained session activity. Internal monitoring should also cover unusual Kerberos validation, SMB authentication and directory enumeration originating from systems or accounts connected to the affected gateway.

Because the operation reportedly uses valid credentials and session cookies, detection cannot depend entirely on malware alerts or repeated failed logins. A successful login from an unusual source, or an authenticated session that behaves differently from the account’s normal pattern, may be more relevant.

CISA and federal agencies recommend credential and session resets

CISA previously urged Fortinet customers to enable phishing-resistant authentication and terminate active SSL VPN and administrative sessions. It also recommended resetting Fortinet VPN and administrator passwords, reviewing logs for suspicious behavior, and using PBKDF2 for administrator credential storage.

These measures address separate parts of the access chain. Password resets invalidate known credentials, while session termination is needed to disrupt attackers who already possess authenticated cookies or active sessions. Phishing-resistant authentication can reduce the usefulness of a password alone.

Organizations that suspect compromise should not limit the response to changing a single account. The FBI and USSS advised isolating affected devices, preserving relevant artifacts and logs, applying appropriate countermeasures, and reporting the incident to both agencies.

The internal investigation should account for activity beyond the Fortinet appliance. That includes reviewing privileged accounts, directory-service access, SMB connections and sensitive network shares that may have been reached after the initial login.

FortiBleed’s operational risk comes from that progression: previously stolen credentials can reopen perimeter access, intercepted authentication data can expand the credential pool, and newly created accounts can keep the intrusion alive after the original password is changed.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →