FortiBleed: FBI says 86,644 FortiGates compromised, lockouts continue
FortiGate admin lockout stolen VPN credentials

FortiBleed: FBI says 86,644 FortiGates compromised, lockouts continue

A fully patched FortiGate can still be someone else's firewall. The FBI and U.S. Secret Service say the FortiBleed credential campaign is still logging into exposed devices and, in some cases, locking the real admins out.

What happened

On 6 October 2026 the agencies published joint advisory JCSA-20261006-01. They cite SOCRadar's count of more than 86,644 compromised FortiGate firewalls and SSL VPN gateways across 194 countries. Attackers scan for internet-facing portals, stuff and spray credentials from earlier leaks and infostealer logs, pull user databases and session material, and crack hashes offline.

Once in, they create new admin accounts. Some victims then find original accounts disabled or passwords changed. The advisory also ties the access to ransomware affiliates of INC/Lynx and Payload. This is not a new firmware bug. There is no patch for a stolen password.

Who is affected

Any organisation with an internet-facing FortiGate firewall or FortiGate SSL VPN, including sites that already installed current FortiOS. Reused local passwords and exposed management interfaces are the exposure, not an unpatched CVE.

  • Internet-facing SSL VPN and admin portals are the entry point.
  • Lockout is possible if the attacker changes or deletes the original admin.
  • Stolen access is being offered to ransomware affiliates, so a quiet login is not a harmless login.

What to do now

Take management off the internet, terminate admin and VPN sessions, reset local credentials, and turn on phishing-resistant MFA. Review every firewall and VPN user for accounts you did not create. Hunt authentication logs for stuffing and for new admins. If you are already locked out, treat it as a compromise, not a forgotten password.

Source: The Record, FBI, Secret Service add to warnings of FortiBleed credential stealing campaign. Advisory PDF: JCSA-20261006-01.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

MonsterCloud CEO charged over secret ransom payments
Recovery firm allegedly paid attackers, then billed victims far more