FortiBleed: FBI Warns the Campaign Against FortiGate Devices Is Ongoing
On October 9, 2026, the FBI and Secret Service issued an advisory on the FortiBleed campaign, which is compromising internet-exposed FortiGate firewalls and SSL VPN gateways across all 16 critical infrastructure sectors. For anyone running industrial networks, the IT/OT boundary is the first place to check.
On October 9, 2026, the FBI and the U.S. Secret Service published an advisory (IC3 CSA 2026/261006) warning that the credential-compromise campaign known as FortiBleed continues to target internet-facing FortiGate firewalls and SSL VPN gateways. Affected organizations may lose access to their own devices.
According to a summary of the advisory published by Industrial Cyber, SOCRadar has verified more than 86,644 compromised devices in 194 countries. The advisory covers all 16 critical infrastructure sectors, including energy, water and wastewater, healthcare, communications and transportation. The information below is drawn from that summary, not from a direct reading of the advisory.
How the attack chain works
The operation is methodical and largely automated. The attackers:
- scan for exposed FortiGate SSL VPN portals;
- apply credential stuffing and password spraying, using old Fortinet data dumps and infostealer logs;
- crack password hashes offline, stored with legacy SHA-256, on a distributed GPU cluster running Hashcat and Hashtopolis;
- filter valid credentials to discard honeypots, then rank them by the victim's revenue and network structure;
- create new administrative accounts on the firewall to establish persistence;
- enumerate Active Directory, keep spraying passwords to find privileged accounts, and package the access for sale.
Attackers can also delete existing accounts or change passwords, locking the organization out of its own device.
The ransomware connection
The agencies report that this chain has been used as an initial access vector by ransomware affiliates, including INC/Lynx and Payload. The operation came to light because its operators mistakenly left the backend server exposed through an open directory, giving researchers a rare, complete view of how it works.
Why this matters for plant operators
In many plants, the perimeter firewall or VPN is the only path between the IT network and the production network. A compromised administrative account on that device is not just an IT problem: it can open the way into OT. The lockout risk adds an operational dimension, because an organization that loses control of its firewall may have no means to isolate or reconfigure the perimeter at the worst possible moment.
If an attacker can delete administrative accounts, the recovery plan cannot depend on those same accounts.
What to do now
The actions recommended by the agencies are:
- restrict management access from the internet;
- terminate active administrator and VPN sessions;
- reset credentials;
- enforce phishing-resistant MFA.
Some practical checks can complement this guidance: review Fortinet administrative accounts for unknown or missing users, examine credential reuse across systems, and remove management interfaces from the internet. Because accounts can be deleted, it is worth preparing an out-of-band recovery path, such as a separate, documented console or management access.
A caution on indicators of compromise
The advisory lists IP addresses associated with a command-and-control server, proxy nodes and a beacon relay. Some may belong to reassigned cloud addresses, so they should be treated as historical data and compared against current network logs, rather than drawing conclusions from a simple match.
The underlying message is that the campaign does not exploit a sophisticated flaw, but weak, reused or already-leaked credentials on exposed devices. Reducing the exposed surface and hardening authentication remains the most concrete defense.