Back to Newsroom
Threat Intel

FBI Warns Fortinet Credential-Harvesting Campaign Is Still Active

The FBI and U.S. Secret Service say the FortiBleed campaign against FortiGate firewalls and SSL VPN gateways continues to harvest working credentials worldwide, with attackers planting rogue admin accounts to keep access even after a reset.

FBI Warns Fortinet Credential-Harvesting Campaign Is Still Active

Federal investigators say a sprawling credential-harvesting operation against internet-facing FortiGate firewalls and SSL VPN gateways is still active, with attackers continuing to exploit weak or reused passwords and an outdated hashing scheme to break into devices at scale.

What happened

The FBI and the U.S. Secret Service issued a joint advisory warning that the campaign, tracked as FortiBleed, has harvested working credentials for tens of thousands of Fortinet devices across more than 190 countries. The operation follows a five-stage playbook: attackers scan the internet for exposed Fortinet portals, break in using credential stuffing and password spraying fed by data from past breaches and infostealer logs, then deploy a custom passive-sniffing tool to intercept authentication traffic across dozens of network protocols.

Captured password hashes are routed to a dedicated cracking cluster for offline recovery. Once cracked, the credentials are validated, filtered to weed out honeypots, and mapped to organizations by revenue and network structure — turning stolen passwords into a prioritized target list. From there, attackers move laterally, enumerate Active Directory, validate Kerberos tickets, and authenticate to file shares, often creating new administrative accounts on the firewall itself to guarantee continued access even if the original credentials are rotated.

Investigators believe the group behind the campaign functions as an initial access broker, harvesting and packaging credentials for resale to other threat actors — including, based on observed operator overlap, affiliates of the INC and Lynx ransomware operations.

Why it matters

A compromised FortiGate or SSL VPN gateway is a direct line into the internal network it's meant to protect. Because attackers create their own administrative accounts — and in some cases delete the legitimate ones — organizations can find themselves locked out of their own perimeter device while the threat actor retains full control. Persistent authenticated access through stolen session cookies also means the compromise can outlast a simple password reset.

The reliance on credential reuse and legacy password hashing, rather than a new software exploit, is a reminder that authentication hygiene remains one of the highest-leverage defenses against large-scale, automated intrusion campaigns.

What to do

  • Enable phishing-resistant multi-factor authentication on all FortiGate administrative and SSL VPN access.
  • Terminate all active VPN and administrative sessions, then force a credential reset using PBKDF2 for administrator password storage.
  • Audit the local account list on every Fortinet device for unfamiliar or unauthorized administrator accounts.
  • Review authentication and session logs for signs of password spraying, unexpected logins, or newly created accounts.
  • Treat any FortiGate device with internet-facing management or SSL VPN as high priority for isolation and forensic review if compromise is suspected.
  • Report confirmed incidents to the FBI and U.S. Secret Service.
SHARE