Fortinet FortiBleed Attacks Lock Out Firewall Admins

Fortinet customers are being urged to move quickly after the FBI and U.S. Secret Service warned that the FortiBleed credential-compromise campaign is still actively targeting internet-facing FortiGate firewalls and SSL VPN gateways and, in some cases, locking legitimate administrators out of their own devices[7][9][14]. The joint advisory, issued on October 6, says the operation has escalated from large-scale credential harvesting to disruptive activity that can impede incident response and create a stepping stone for ransomware and other follow-on attacks[6][8][12].

FortiBleed operators focus on exposed Fortinet appliances and rely heavily on stolen, reused, or leaked credentials, as well as weaknesses in legacy password storage, rather than on a single software flaw that can be fixed with a patch[4][13]. The campaign is hitting critical infrastructure networks globally, with threat intelligence firm SOCRadar estimating 86,644 compromised FortiGate devices across 194 countries, a figure cited in the FBI and Secret Service alert and subsequent industry reporting[7][13]. That reliance on credentials means the risk persists even for organizations that keep up with routine Fortinet software updates, because the core problem lies in how accounts and secrets are managed and stored[4][13].

Once attackers obtain valid FortiGate or VPN credentials, they log into management interfaces on internet-facing devices, create new privileged accounts, and change or delete existing administrator profiles and passwords[9][10][12]. Several victims reported being fully locked out of their appliances when threat actors disabled original accounts or altered their credentials, effectively handing control of those firewalls and gateways to the intruders[6][8][10]. The advisory notes that FortiBleed actors have used this persistence to move laterally, harvest additional authentication data at scale, and, in some cases, position themselves for ransomware deployment and other high-impact operations[6][12].

U.S. agencies are warning that recovering from a FortiBleed compromise often requires more than standard patching and password resets because attackers may retain access through hidden or newly created admin accounts and backdoor configurations[4][6][9]. Organizations are being told to assume exposed Fortinet devices may be tampered with and to plan for more invasive remediation steps, such as auditing all local and remote administrator profiles, validating configuration integrity, and, where necessary, rebuilding appliances from trusted baselines before restoring production traffic[6][9][12].

To reduce the attack surface, the FBI and Secret Service recommend that Fortinet customers restrict or eliminate internet-facing administrative access, using trusted-host restrictions, local-in policies, or removing external management entirely for FortiGate devices[1][5][11]. The advisory also calls for terminating all active administrative and VPN sessions, resetting all VPN and management passwords, enforcing phishing-resistant multi-factor authentication, and enabling secure credential storage on Fortinet appliances[1][6][9]. Teams are urged to review firewall and VPN user lists for unauthorized changes, comb through logs for suspicious activity and lateral movement, and closely monitor for new or modified accounts that could indicate FortiBleed persistence[6][11][12].

Security analysts say the FortiBleed campaign underscores a broader shift in how attackers target network edge equipment, treating firewalls and VPN gateways as high-value identity and access hubs rather than merely perimeter devices[6][13]. Critical infrastructure operators, in particular, are being encouraged to treat credential hygiene and secure storage on these appliances as a priority, to integrate Fortinet logs into centralized monitoring, and to rehearse lockout scenarios so they can rapidly regain control if FortiBleed or similar operations succeed[4][6][11]. With more than 86,000 devices already believed compromised and attacks still ongoing, defenders are being warned not to assume that a reachable FortiGate or VPN gateway is under their exclusive control until thorough checks have been completed[7][9][13].

References

  1. FortiBleed campaign still attacking Fortinet devices, US agencies warn
  2. Agencies warn of credential-compromising campaign actively targeting critical infrastructure networks | AHA News
  3. FortiBleed Campaign Exploits Fortinet Firewalls and VPNs, FBI Warns
  4. Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
  5. FBI and Secret Service Warn of FortiBleed Lockout Threat
  6. FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users
  7. FBI: Ongoing FortiBleed attacks lock out FortiGate VPN …
  8. FortiBleed is still active, with attackers locking admins out …
  9. FortiBleed still a bleeding nuisance as FBI confirms ongoing …
  10. FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials
  11. FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away
  12. Fortinet — Latest News, Reports & Analysis | The Hacker News

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply