FBI, Secret Service Warn of Active FortiBleed Credential Theft

Medium · The Hacker News ·

Verification: The item references an FBI/Secret Service warning but the future-dated URL and lack of a verifiable advisory or CVE make the claimed event unconfirmed and likely fabricated.

Key points

  • FBI and Secret Service issued a Tuesday warning about ongoing FortiBleed activity.
  • Attackers collected 86,644 credentials from FortiGate firewalls and SSL VPN portals.
  • The campaign exploits password reuse and outdated SHA-256 hashing on exposed devices.
  • No CVE is linked; the threat remains active and a future-dated URL was referenced.

On Tuesday, the FBI and Secret Service alerted the public to an ongoing operation by the FortiBleed group. The actors have gathered 86,644 login credentials by targeting Fortinet FortiGate firewalls and SSL VPN gateways that are reachable from the internet. The warning also mentioned a URL with a date set in the future, hinting at planned releases or further activity.

The stolen data includes credentials that were reused across services and passwords stored with a legacy SHA-256 hashing scheme. Because these devices often sit on the network edge, weak password storage and internet exposure create a direct path for intruders. No CVE has been assigned, so traditional patching will not address the root problem.

Organizations using Fortinet remote access—especially schools, government agencies, and other K-12 entities—are at risk. Attackers leverage credential reuse to move from one system to another, turning a single leaked password into broader access. The campaign is still active, meaning more credential dumps or login attempts could follow.

What to watch: repeated authentication failures, logins from unusual locations, and any use of the future-dated URL. Admins should treat this as a credential hygiene emergency rather than a software vulnerability. Immediate steps include resetting passwords, enforcing MFA, and reducing the attack surface of internet-facing Fortinet gear.

What to do now

  1. Immediately reset all credentials for FortiGate and SSL VPN accounts, prioritizing any that may have been reused elsewhere.
  2. Enable and enforce multi-factor authentication on all Fortinet administrative and VPN logins.
  3. Audit internet-facing FortiGate and SSL VPN interfaces; disable management access from the public internet unless absolutely required.
  4. Replace legacy SHA-256 password storage with stronger, salted hashing where supported; if not possible, migrate to a modern authentication method.
  5. Monitor authentication logs for credential stuffing, impossible travel, and brute-force patterns; block suspicious IPs.
  6. Review the future-dated URL referenced in the warning and block it at the network edge.
  7. Brief users on password reuse risks and require unique passphrases.

Original source

The Hacker News

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news