ON 6 October 2026, a joint Cybersecurity Advisory from the FBI and the U.S. Secret Service warned that FortiBleed remains an active global credential‑harvest campaign targeting internet‑facing Fortinet FortiGate firewalls and Fortinet SSL VPN gateways. SOCRadar’s Threat Research Unit notes this campaign continues to scale, with more than 86,644 confirmed compromised devices across 194 countries, and ongoing activity as attackers scan exposed Fortinet devices and reuse previously obtained credentials.
The disruption now includes administrators being locked out of their own FortiGate devices, as attackers establish new admin accounts for persistence while sometimes deleting or altering legitimate accounts. Recovery requires more than routine patching or password resets; organisations must ensure out‑of‑band administrative recovery for edge devices and plan for scenarios where credential resets do not restore access.
The operational flow remains driven by commodity techniques: credential stuffing and password spraying using leaked Fortinet data, offline cracking of exfiltrated hashes via GPU clusters, and subsequent interior access guided by Active Directory enumeration to locate privileged accounts. Indications to hunt include anomalous account names (e.g., admin, fortiAdmin, itadmin) and exploratory activity around SSH or REST API keys, which can persist beyond password resets.
The advisory highlights mitigations to shrink attack surfaces, terminate sessions, enforce phishing‑resistant MFA, and validate configurations, with guidance to use CISA’s Eviction Strategies Tool for planning containment. SOCRadar’s check tool offers a free FortiBleed exposure scan to determine whether an organisation’s FortiGate or Fortinet VPN credentials appear in the breach dataset.