FortiBleed: FBI says 86,644 FortiGate devices still locked out
Ongoing credential reuse against FortiGate firewalls and SSL VPN gateways

FortiBleed: FBI says 86,644 FortiGate devices still locked out

The FBI is warning that FortiBleed attacks are still active. Exposed Fortinet FortiGate firewalls and SSL VPN gateways are being taken over with previously leaked credentials, infostealer logs, credential stuffing, and password spraying. In some cases the attacker then deletes admin accounts or changes their passwords, locking the real administrators out.

What happened

FortiBleed surfaced in June 2026, when a backend server exposed usernames and plaintext passwords tied to 73,932 firewall URLs across 194 countries. SOCRadar's latest count is about 86,644 confirmed-compromised devices, not a mere exposure estimate. Devices breached months ago remain in the actor's inventory.

Attackers pull password hashes from compromised appliances and crack them offline on a GPU cluster. The FBI says the chain has been used as initial access for INC/Lynx and Payload ransomware affiliates. A joint FBI and US Secret Service notice this week says remediation can require more than a password reset.

Who is affected

  • Internet-facing FortiGate firewalls and SSL VPN gateways, especially any appliance whose credentials appeared in the June leak
  • Organisations that reset a password but left management or VPN sessions alive
  • Sites still storing administrator passwords with legacy hashes instead of PBKDF2

What to do now

Treat a previously exposed FortiGate as compromised until you prove otherwise. Restrict internet-facing management, terminate every admin and VPN session, reset credentials, and turn on phishing-resistant MFA. Review firewall, VPN, authentication, and domain-controller logs for new accounts and lateral movement. Enforce PBKDF2 for administrator password storage.

Source: BleepingComputer, FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

PoeLLM mined more than 3,400 AI servers
LiteLLM, Ollama, Gotenberg and Gitea recruited since April