As reported by The Hacker News, the FBI and USSS have confirmed that the FortiBleed credential harvesting campaign remains an active and ongoing threat, with over 86,644 Fortinet device credentials already harvested across 194 countries. The scale is staggering, but the technical root cause is embarrassingly mundane: legacy SHA-256 password hashing and credential reuse.
Why This Campaign Succeeds Where Others Fail
FortiBleed isn't exploiting a zero-day. It's exploiting operational hygiene. The five-stage pipeline—reconnaissance, credential stuffing, traffic interception via the Go-based FortigateSniffer tool, GPU-accelerated hash cracking, and lateral movement—works because two conditions persist across thousands of deployments:
- Legacy SHA-256 password storage: SHA-256 is a fast hash. It was never designed for password storage. Without salting and key stretching, modern GPUs can crack these hashes at rates that make offline brute-force trivial. Fortinet's move to PBKDF2 addresses this, but only for administrators who have actually migrated.
- Credential reuse from prior breaches: The campaign feeds infostealer logs and leak dumps into credential stuffing engines. Any organization where firewall admin credentials overlap with previously breached accounts is effectively already compromised—they just don't know it yet.
The most alarming detail isn't the credential count. It's that the attackers are filtering out honeypots, mapping organizations by revenue, and prioritizing high-value targets. This is a business operation with a CRM pipeline, not a spray-and-pray script.
Who Is Most Exposed
Organizations at highest risk share these characteristics:
The Broader Pattern: Network Appliances Are the New Perimeter Target
FortiBleed fits a now-established pattern. Network edge devices—firewalls, VPN concentrators, load balancers—have become primary initial-access vectors because they sit at the trust boundary, often run legacy authentication stacks, and are frequently managed by teams outside the core security organization. We saw this with FortiOS SSL-VPN flaws in 2024, Ivanti in 2023-2024, and PAN-OS issues in 2025. The appliance is the new endpoint.
What distinguishes FortiBleed is that no product vulnerability is being exploited. The fault lies entirely in configuration and credential management. That means no patch will save you—only operational discipline will.
Shield53 Recommendations
Immediate Actions (Within 24 Hours)
- Terminate all active SSL VPN and administrative sessions on every FortiGate appliance. This forces re-authentication and invalidates any session cookies the attackers may hold.
- Reset all Fortinet VPN and administrative passwords. Generate new credentials with a password manager—no reuse, no patterns. Rotate the admin account name if a default like
adminoradministratoris in use. - Restrict administrative interfaces to a management VPN or allowlist of trusted IPs. No FortiGate admin interface should be reachable from the open internet.
Hardening Actions (Within 72 Hours)
- Enable phishing-resistant MFA on all administrative and VPN accounts. Push-based or hardware-token MFA—SMS is not acceptable against this threat.
- Migrate to PBKDF2 password storage if you haven't already. Verify the migration completed by checking the FortiGate configuration or consulting Fortinet's advisory documentation.
- Audit for new or unfamiliar administrative accounts on all firewalls. FortiBleed creates persistence accounts—find and remove them.
- Review authentication logs for the past 90 days. Look for: credential stuffing patterns (rapid sequential login attempts), logins from unexpected geographies, and new admin account creation events.
Detection Guidance
- Monitor FortiGate logs for
FortigateSnifferbehavioral indicators: unexpected outbound connections from the firewall itself, unusual process activity, or anomalous traffic capture on interfaces not configured for packet capture. - Watch for Kerberos and SMB authentication attempts originating from the firewall's IP address—this indicates lateral movement has begun.
- Alert on any new local account creation on FortiGate appliances outside of planned change windows.
Strategic Recommendation
Treat every network edge appliance as a Tier-0 asset. Apply the same credential hygiene, MFA enforcement, and logging rigor you'd apply to a domain controller. The firewall is the gate to your kingdom—and right now, 86,644 keys to that gate are in someone else's hands.