thehackernews.com 7 Oct 2026, 11:56 UTC

FBI Warns FortiBleed Attackers Are Still Stealing Fortinet Credentials

THE FBI and US Secret Service have warned that the FortiBleed credential-harvesting operation remains active against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The campaign is believed to rely on reused or leaked credentials and legacy SHA-256 password storage to harvest authentication data at scale, with attackers continuing to scan for exposed Fortinet devices using previously obtained credentials.

Since first documented by SOCRadar in June 2026, the operation is estimated to have harvested more than 86,644 working device credentials across 194 countries as of 19 June 2026. Experts have previously urged Fortinet customers to enable phishing-resistant authentication, terminate active SSL VPN and admin sessions, reset VPN and admin passwords, adopt PBKDF2 for admin credential storage, and review logs for signs of suspicious activity.

FortiBleed operates as a five-stage campaign: reconnaissance to identify exposed portals, credential stuffing and password spraying against those devices using leaked data and infostealer logs, deployment of a Go-based tool called FortigateSniffer to passively intercept authentication traffic across 24 protocols and harvest credentials and password hashes, offline cracking with GPU clusters using Hashcat and Hashtopolis, and then using cracked credentials for lateral movement, Active Directory enumeration, Kerberos validation, SMB authentication, and data exfiltration from network shares.

The attackers are believed to enrich and prioritise targets, create new administrative accounts to maintain persistence, and may move deeper into victim networks. In some cases, original accounts are deleted to lock organisations out of their devices, while new accounts enable continued access and lateral movement. If compromise is detected, organisations should isolate affected devices, collect artifacts and logs, report to the FBI and USSS, and apply countermeasures to mitigate the threat.

View full article

Article by CyberSIXT