Computers

FBI says FortiBleed attacks on Fortinet firewalls are still ongoing

The FBI warns that FortiBleed attacks continue to target exposed Fortinet FortiGate firewalls and SSL VPN gateways, benefiting ransomware groups.

The FBI has issued a warning that FortiBleed attacks targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways are still ongoing, according to bleepingcomputer.com.

Hackers are gaining access using leaked credentials, infostealer logs, credential stuffing, and password spraying attacks. Attackers then extract authentication data and crack stolen password hashes offline using a distributed GPU cluster running Hashcat and Hashtopolis.

The FBI states the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates. The INC/Lynx ransomware and Payload ransomware groups are benefiting from these attacks.

The FBI also says threat actors create administrator accounts to delete or change passwords of existing admin accounts, denying victims access.

The FBI recommends remediation measures beyond patching, including restricting external access, terminating active VPN sessions, enforcing MFA, and reviewing logs. It also recommends enforcing PBKDF2 for administrator password storage.

Background

FortiBleed is a massive Fortinet credentials leak discovered in June 2025, exposing usernames and plaintext passwords for 73,932 firewall URLs across 194 countries. In July 2025, SOCRadar linked FortiBleed to the INC and Lynx ransomware operations. By SOCRadar's latest count, FortiBleed compromised 86,644 devices.

Quick answers

What is FortiBleed?

FortiBleed is a massive Fortinet credentials leak discovered in June 2025, exposing usernames and plaintext passwords for 73,932 firewall URLs across 194 countries.

What should organizations do to protect against FortiBleed attacks?

The FBI recommends restricting external access, terminating active VPN sessions, enforcing MFA, reviewing logs, and enforcing PBKDF2 for administrator password storage.

Source