FBI and Secret Service Warn FortiBleed Campaign Still Active, 86,644 Fortinet Credentials Stolen and Admins Locked Out

FBI/Secret Service warn FortiBleed campaign active: 86,644 Fortinet firewall credentials stolen, admins locked out. K-12/govt mitigation steps.

  • FBI and Secret Service warn FortiBleed credential harvesting campaign is still active, with 86,644 Fortinet firewall/VPN credentials stolen.
  • Attackers are locking out legitimate admins from FortiGate devices after gaining access, hindering incident response.
  • No CVE to patch; mitigation requires credential resets, MFA enforcement, restricting management access, and log monitoring.

What to do now

  1. Inventory all internet-facing FortiGate firewalls and SSL VPN gateways, then disable or restrict management access from the public internet.
  2. Reset all administrative and VPN credentials immediately, enforce MFA for every account, and remove stale or unknown accounts.
  3. Review authentication and configuration logs for lockouts, deleted accounts, unexpected password changes, and suspicious VPN sessions; preserve evidence.
  4. Apply the latest Fortinet firmware and follow the joint FBI/Secret Service advisory mitigation guidance—even though no CVE is associated.
  5. Segment management interfaces, back up configurations offline, and test recovery procedures including out-of-band console access.

Related items