FBI and Secret Service Warn FortiBleed Campaign Still Active, 86,644 Fortinet Credentials Stolen and Admins Locked Out
FBI/Secret Service warn FortiBleed campaign active: 86,644 Fortinet firewall credentials stolen, admins locked out. K-12/govt mitigation steps.
- FBI and Secret Service warn FortiBleed credential harvesting campaign is still active, with 86,644 Fortinet firewall/VPN credentials stolen.
- Attackers are locking out legitimate admins from FortiGate devices after gaining access, hindering incident response.
- No CVE to patch; mitigation requires credential resets, MFA enforcement, restricting management access, and log monitoring.
What to do now
- Inventory all internet-facing FortiGate firewalls and SSL VPN gateways, then disable or restrict management access from the public internet.
- Reset all administrative and VPN credentials immediately, enforce MFA for every account, and remove stale or unknown accounts.
- Review authentication and configuration logs for lockouts, deleted accounts, unexpected password changes, and suspicious VPN sessions; preserve evidence.
- Apply the latest Fortinet firmware and follow the joint FBI/Secret Service advisory mitigation guidance—even though no CVE is associated.
- Segment management interfaces, back up configurations offline, and test recovery procedures including out-of-band console access.
Related items
- FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away
- Apache Struts: Apache Struts Command Injection Vulnerability
- Microsoft, Adobe, Apple, and Foxit vulnerabilities
- FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
- Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
- Ransomware has a new target. Is your backup ready?
- FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
- FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins