FortiBleed Attacks Compromise 86,644 FortiGate, SSL VPN Systems in 194 Countries
Moyen · Help Net Security ·
En bref
- Attackers targeted FortiGate firewalls and SSL VPN gateways, affecting 86,644 devices in 194 countries.
- The campaign locks administrators out, deletes or changes passwords, and causes access loss.
- Fortinet, the FBI, the U.S. Secret Service, SOCRadar and Help Net Security are involved in verification and advisory efforts.
- No CVE has been assigned; severity is medium.
On October 7, 2026, details emerged about a campaign by actors tracked as FortiBleed, a threat actor focused on Fortinet perimeter products. The operation has hit FortiGate firewalls and SSL VPN gateways, with 86,644 compromised devices identified across 194 countries. Rather than only stealing data, the intruders are disrupting management access: they lock admins out, delete passwords, and change passwords, leaving organizations unable to reach their own equipment.
Fortinet, the FBI, the U.S. Secret Service, SOCRadar, and Help Net Security are among those verifying compromises and issuing an advisory. The impact is both immediate and operational: administrator lockout, device compromise, and loss of access can sever remote connectivity, interrupt monitoring, and force emergency recovery. Because these appliances often sit at the network edge, a single compromised firewall or VPN gateway can expose or isolate entire sites.
The scale—tens of thousands of systems in nearly every country—suggests broad opportunistic scanning and exploitation rather than a narrow targeted intrusion. No CVE has been assigned, which may complicate tracking and patching decisions; defenders should not wait for a vulnerability identifier to treat the activity as urgent. The medium severity hint reflects that while the campaign is widespread, its primary observed effect is access disruption rather than confirmed destructive payloads.
Affected organizations should assume that any exposed FortiGate or SSL VPN service could be at risk until verified. Administrators need to check for unauthorized credential changes, unexpected admin lockouts, and missing accounts. They should also review logs for password deletions or modifications and coordinate with Fortinet support and relevant authorities if compromise is suspected.
What to watch: further advisories from Fortinet and government partners, updated indicators from SOCRadar and Help Net Security, and any expansion beyond Fortinet products. Until then, prioritize inventory, external exposure reduction, and rapid credential recovery for edge devices.
À faire maintenant
- Inventory every internet-facing FortiGate firewall and SSL VPN gateway; disable or restrict management access from untrusted networks immediately.
- Check for administrator lockouts, deleted accounts, and unexpected password changes; restore access through out-of-band console or Fortinet support if locked out.
- Rotate all local and remote administrative credentials, enable MFA, and remove stale or unknown accounts.
- Apply the latest Fortinet firmware and vendor guidance; if no CVE exists, follow the advisory's mitigation steps rather than waiting.
- Review logs for password deletions, credential modifications, and suspicious VPN sessions; preserve evidence for incident response.
- Contact Fortinet, the FBI, or the U.S. Secret Service if compromise is confirmed or suspected, and share indicators with SOCRadar and Help Net Security as appropriate.
- Segment management interfaces, back up configurations offline, and test recovery procedures to reduce future lockout impact.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.