www.infosecurity-magazine.com 8 Oct 2026, 08:40 UTC

FortiBleed attacks persist as hackers abuse stolen Fortinet credentials

US authorities warn that the FortiBleed campaign against Fortinet FortiGate firewalls and SSL VPN gateways remains active, with widespread credential abuse enabling unauthorised access. An FBI and US Secret Service notice on 6 October cites SOCRadar data suggesting that 86,644 devices across 194 countries have been affected. Attackers reportedly use compromised, previously stolen credentials obtained from Fortinet-related dumps, then employ credential stuffing and password spraying to breach exposed gateways.

Once inside, they create new administrative accounts and move laterally through Active Directory, using GPU-accelerated password cracking with Hashcat and Hashtopolis to turn plaintext credentials, harvested from prior leaks and infostealer logs, into usable access.

Evidence highlighted by law enforcement includes ongoing scans of internet-exposed Fortinet devices and the use of automated tooling to identify targets and prioritise high-value organisations. The attackers’ objective appears to be persistent access rather than rapid ransom, enabling continued monitoring and potential data exfiltration.

Practical response guidance from the notice emphasises isolating compromised hosts, conducting threat hunting, terminating sessions, and resetting credentials, alongside hardening management access, enabling phishing-resistant MFA, and reviewing firewall/VPN configurations and logs for signs of compromise. Organisations are urged to use PBKDF2 for secure credential storage and to review authentication and domain controller activity for lateral movement.

The narrative underscores the danger of silent persistence, with experts warning that attackers seek to remain undetected inside networks for extended periods.

View full article

Article by CyberSIXT