The U.S. Federal Bureau of Investigation (FBI) and the U.S. Secret Service (USSS) issued a joint warning on Tuesday that the FortiBleed credential harvesting campaign remains an active threat targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. According to the advisory, the operation has already amassed 86,644 sets of Fortinet device credentials, exploiting reused or leaked passwords and legacy SHA-256 password storage to compromise vulnerable systems.

What is FortiBleed?

FortiBleed is a large-scale credential harvesting campaign that specifically targets Fortinet FortiGate firewalls and SSL VPN appliances exposed to the internet. The attackers leverage a combination of credential stuffing with previously leaked or reused passwords and weaknesses in how older Fortinet devices store password hashes. By exploiting these weaknesses, the campaign is able to authenticate to devices without needing to crack strong, unique passwords.

The FBI and USSS warn that the campaign is not a one-time event. It remains active, and the stolen credentials are likely being used for follow-on intrusions, including lateral movement, data exfiltration, and ransomware deployment.

How the Attack Works

According to the joint advisory, the threat actors behind FortiBleed exploit two primary weaknesses:

  1. Reused or leaked credentials – Many organizations use the same passwords across multiple services, and when those passwords appear in public breach dumps, attackers can use them to log into Fortinet devices.
  2. Legacy SHA-256 password storage – Older Fortinet firmware versions store password hashes using SHA-256 without proper salting or with weak salting, making it easier for attackers to crack or bypass authentication once they obtain the hash.

The campaign scans the internet for exposed FortiGate and SSL VPN interfaces, then attempts to authenticate using large lists of known credentials. Successful logins are harvested and added to the growing cache of 86,644 credentials.

Why This Matters

Fortinet devices are widely deployed at the network edge, acting as the primary security gateway for many organizations. Compromise of these devices can give attackers a foothold inside the network, allowing them to bypass other security controls, establish persistence, and move laterally to high-value systems.

The scale of the credential cache—over 86,000 unique device credentials—indicates that the campaign has been running for an extended period and has been highly successful. The FBI and USSS are urging organizations to assume that any internet-facing Fortinet device with weak or reused credentials may already be compromised.

Recommended Mitigations

The advisory provides several steps that defenders should take immediately:

  • Audit all Fortinet devices – Check for unauthorized access, unusual configuration changes, or unexpected admin accounts. Review logs for authentication attempts from unfamiliar IP addresses.
  • Enforce strong, unique passwords – Ensure that all Fortinet device passwords are unique and complex. Do not reuse passwords from other services.
  • Enable multi-factor authentication (MFA) – Where supported, enable MFA for all administrative and VPN access. This adds a critical layer of defense even if credentials are stolen.
  • Upgrade firmware – Move to the latest FortiOS versions that use stronger password storage mechanisms (e.g., salted SHA-512 or better). Legacy SHA-256 storage should be considered insecure.
  • Restrict internet exposure – Limit access to FortiGate management interfaces and SSL VPN portals to trusted IP ranges or require VPN access for administration.
  • Monitor for indicators of compromise – The advisory includes IOCs such as specific IP addresses, user agents, and file hashes associated with the campaign. Organizations should hunt for these in their environments.
  • Reset credentials – If a device is suspected of compromise, reset all credentials, revoke active sessions, and reimage the device if necessary.

Broader Implications

The FortiBleed campaign is a reminder that edge devices remain a prime target for attackers. They are often internet-facing, run complex software, and may not receive the same level of patching and monitoring as internal servers. The combination of credential reuse and weak password storage creates a perfect storm for mass exploitation.

Organizations should also consider that the stolen credentials may be used in future attacks, even if the initial compromise is remediated. Continuous monitoring and threat hunting are essential.

Conclusion

The FBI and USSS warning makes it clear that FortiBleed is not a passing threat. With 86,644 Fortinet device credentials already harvested, the campaign has demonstrated its effectiveness and persistence. Defenders must act now to secure their Fortinet infrastructure, enforce strong authentication, and assume that any exposed device with weak credentials is at risk.

For the full advisory and a complete list of indicators of compromise, refer to the original report from The Hacker News: FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials.

Stay vigilant, and keep your edge devices locked down.