Breaking
Cyber CrimeConfirmed

FortiBleed Credential Theft Still Active, FBI Says

The FBI and Secret Service say the FortiBleed campaign remains active, with 86,644 Fortinet device credentials amassed across 194 countries.

··2 hours ago·6 min read
a rack of electronic equipment in a dark room
Photo by Tyler on Unsplash

The credentials harvested from internet-facing Fortinet FortiGate firewalls and SSL VPN gateways remain in circulation, and the agencies tracking the campaign say the operation behind them has not gone quiet. On Tuesday, the FBI and U.S. Secret Service put out a warning that FortiBleed is still an active threat, according to the agencies' statement. The campaign, which security researchers flagged earlier this year, has already produced a large pool of working logins.

86,644 Credentials Across 194 Countries

The scale of the operation is the part that stands out. FortiBleed is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026, according to the source. The campaign was first documented by SOCRadar in Hudson Rock in June 2026. The activity targeted thousands of Fortinet firewalls as part of a global campaign, and the source describes the operation as Russian-speaking.

That number represents working credentials, not just exposed hashes. The figure matters because it means the attackers did not stop at collecting authentication data — the source states they processed it into usable logins.

Reused Credentials and Legacy Storage

The agencies pointed to two conditions that make the campaign effective. In their statement, they said the operation takes advantage of credentials that have been reused or previously leaked, alongside a legacy password storage method.

"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale."

— The FBI and U.S. Secret Service, in the joint statement.

The agencies also described what the attackers are doing now, based on initial findings. "Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials," they said. That language points to ongoing scanning activity, not a completed incident.

Inside the Five-Stage Campaign

FortiBleed unfolds in five stages, according to the source. The first is broad reconnaissance to identify exposed portals. From there, the attackers use credential stuffing and password spraying, drawing on data from prior leak dumps and infostealer logs, to gain access to those devices.

Once inside, they deploy a Go-based tool called FortigateSniffer, which passively intercepts authentication traffic across 24 protocols and harvests credentials and password hashes. The hashes move to a GPU-accelerated cracking cluster that runs Hashmat and Hashtopolis for offline cracking.

After cracking, the source says the credentials are used for lateral movement, Active Directory enumeration, Kerberos validation, and SMB authentication. In the final stage, sensitive data from network shares is exfiltrated, while stolen session cookies are used to maintain persistent, authenticated access.

Sorting and Prioritizing Targets

The processing stage was not haphazard, according to the agencies. Cracked credentials were enriched, sorted, and validated, the source states.

"Cracked credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure."

— The FBI and U.S. Secret Service, in the joint statement.

The same statement notes that new administrative accounts were created on the firewall to maintain persistence. With verified credentials in hand, the attackers moved deeper into victim environments, conducted enumeration, and ran password spraying to expand access and identify privileged accounts, according to the source.

Persistence Through Extra Accounts

Adding new accounts is a recurring tactic described in the source. Initial access is used to add accounts to the system as a way of keeping a foothold on the appliance. The source lists commonly identified compromised account names:

  • adminin
  • fortiAdmin
  • forticloud-sync
  • admin
  • fgtsecure
  • pakedge
  • forticloud-tech
  • districtadmin
  • system_config
  • gttadmin
  • roadmin
  • itadmin
  • Technical_support
  • adminsslvpn
  • IT_Manager
  • my_admin
  • support_fortinet
  • fgtsec
  • forti_support2

The source presents this list as the article's own compilation, not as an FBI or Secret Service advisory. Some of the names mimic routine administrative or support accounts, which is consistent with the source's description of attackers adding accounts that appear legitimate at a glance.

Downstream Buyers and Ransomware Links

The source describes the adversary as suspected to be an initial access broker that packages the stolen information and sells it to downstream threat actors. The source presents this as its own assessment, evidenced by operator overlaps tying FortiBleed to INC and Lynx ransomware operations. Those overlaps, according to the source, likely indicate the access is being abused for ransomware deployment. This is not attributed to the FBI or Secret Service in the source text.

The source states that with verified credentials, attackers have been found to move deeper into victim environments and conduct enumeration and password spraying to expand access and identify privileged accounts.

Lockouts and Deleted Accounts

One consequence the agencies did describe directly is the risk of victim lockouts. "Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," the FBI and USSS said. They elaborated on the mechanism: "During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment."

That scenario turns a credential theft incident into an operational one for defenders, who may find legitimate administrators shut out of the very devices they need to remediate.

What CISA Told Fortinet Customers

The campaign previously prompted the U.S. Cybersecurity and Infrastructure Security Agency to advise Fortinet customers with FortiGate appliances on a set of countermeasures. CISA urged customers to enable phishing-resistant authentication, terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrative passwords, and use PBKDF2 to store administrator credentials, according to the source. It also advised reviewing logs for signs of suspicious activity.

The earlier CISA guidance and the new FBI/USSS warning share a similar posture: assume the credentials are already in circulation and force a reset.

The Numbers Behind the Alert

Several concrete figures anchor the warning:

  • 86,644 working device credentials amassed by the campaign as of June 19, 2026
  • 194 countries spanned by the stolen credentials
  • 24 protocols monitored by FortigateSniffer for authentication traffic
  • June 2026 when SOCRadar in Hudson Rock first documented FortiBleed

The credential count is the largest figure in the source, and it reflects working credentials rather than raw data. The country count shows the spread is not limited to a single region, and the protocol count underscores how much authentication traffic the sniffer observes.

What to Do If You Suspect Compromise

The source lays out a response path for organizations that detect potential compromise. They are advised to isolate the affected devices, collect necessary artifacts and logs, report the incident to the FBI and USSS, and apply relevant countermeasures to mitigate the threat.

The source also notes that initial access is used to add new accounts as a persistence mechanism, so account reviews on FortiGate appliances are part of the picture. Resetting passwords, terminating sessions, and checking for unfamiliar administrator accounts all address the access paths described in the warning.

Why It Matters for Defenders

The warning's core message is that a campaign documented months ago has not been closed out. If the credentials remain valid and the agencies are still seeing scanning activity tied to previously obtained logins, then exposure may not be limited to organizations that were compromised during the original wave. A firewall that was left untouched the first time could still be reachable with a credential that leaked elsewhere and was reused.

The lockout risk adds a practical wrinkle: if attackers delete or change passwords for original accounts, an organization's own response could be slowed by an inability to log in. That suggests account inventories and out-of-band access paths are worth verifying before an incident, not during one. For FortiGate operators, the source's advice points to a straightforward sequence — check for unfamiliar accounts, reset credentials, terminate sessions, and review logs — with the understanding that the threat activity it describes is ongoing.

#fortibleed#fortinet#credential theft#fbi#ransomware

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories