ATTACKERS behind the FortiBleed campaign are compromising Fortinet devices to lock organisations out of their own systems. The operation, which targets internet‑exposed FortiGate firewalls and SSL VPN appliances, began in June and relies on a mix of using previously captured credentials and brute‑force techniques to take control of poorly protected devices.
In many cases, threat actors alter or delete existing Fortinet accounts and reset credentials to prevent legitimate access, leaving victims unable to regain control. The campaign has already affected large numbers of devices across the globe, with initial reporting naming more than 86,000 compromised devices in 190 countries, and recent assessments from SOCRadar indicating about 86,644 devices across 194 countries.
The attackers reportedly search for exposed SSL VPN portals, harvest credentials from infostealer logs and dumps, crack hashed credentials offline, map targets to evade defences, and then sell working VPN configurations and target lists to other actors.
A joint FBI/US Secret Service advisory confirms the operational pattern and the risk to organisations' access to Fortinet appliances. Recommendations focus on containment and prevention: identify compromised hosts, scope the intrusion, evict attackers, and harden protections to deter re‑entry.
Practical mitigations include restricting management access, resetting all Fortinet VPN and administrative passwords, deploying phishing‑resistant MFA, reviewing firewall and VPN user configurations and API keys, and auditing logs for suspicious activity. Organisations are also advised to ensure credentials are securely stored and to validate configurations to reduce the attack surface.