As reported by BleepingComputer, the FBI has issued warnings that the FortiBleed campaign remains actively operational, with threat actors leveraging stolen credentials to compromise exposed Fortinet FortiGate firewalls and SSL VPN gateways — and in many cases, locking out legitimate administrators entirely. This is not a residual cleanup problem. It is an ongoing, monetized access operation with direct ties to ransomware affiliates including INC/Lynx and Payload.
Why This Matters Beyond the Headline
The FortiBleed operation, first surfaced in June 2026 when attackers accidentally exposed their own backend infrastructure, has now compromised over 86,000 devices across 194 countries according to SOCRadar's tracking. What makes this campaign particularly dangerous is not the initial access method — credential stuffing and infostealer-derived logins are well-understood — but the industrial-scale post-access operations that follow.
Attackers are not simply logging in. They are extracting configuration files containing password hashes, then cracking them offline using a distributed GPU cluster running Hashcat and Hashtopolis. This is a purpose-built cracking pipeline. Once administrative credentials are recovered, the attackers create new admin accounts, delete or repassword existing ones, and establish persistent VPN access. The victim is locked out of their own perimeter device while the attacker has a foothold inside the network.
The remediation guidance from the FBI — that patching and password resets alone are insufficient — is the most important takeaway for defenders. This campaign demands full incident response posture, not a maintenance window.
The Hash Problem: SHA-256 vs PBKDF2
One technical detail deserves emphasis. The FBI specifically recommends enforcing PBKDF2 for administrator password storage instead of legacy SHA-256 hashing. SHA-256 is a fast hash — designed for throughput, not password storage. On a distributed GPU rig, SHA-256 hashes fall in minutes to hours depending on complexity. PBKDF2 introduces computational cost through iterations, making offline cracking exponentially more expensive. Any Fortinet deployment still relying on legacy hashing is operating with a fundamentally broken last line of defense.
Who Is Most at Risk
Shield53 Recommendations
Treat any FortiGate device that has had an internet-facing admin or SSL VPN portal in the last 12 months as potentially compromised. Do not assume a password reset is sufficient remediation.
Immediate Actions
- Restrict external management access — move admin interfaces behind VPN, allowlist management IPs, or use an out-of-band management network. No FortiGate admin portal should be broadly internet-accessible.
- Terminate all active VPN sessions — force reauthentication for every user. This closes any persistence the attacker established via active sessions.
- Enforce MFA on all administrative accounts — not just VPN users. Local admin accounts on FortiGate devices must require a second factor.
- Migrate password hashing to PBKDF2 — verify in FortiOS configuration that legacy SHA-256 password storage is disabled. This is your critical defense against offline cracking if configuration data is exfiltrated.
- Audit for unauthorized admin accounts — review the full administrator list on every device. Look for accounts created outside your naming conventions or change windows.
- Hunt for lateral movement — if any device shows signs of compromise (missing admin accounts, changed passwords, unexpected configuration changes), assume the attacker has moved beyond the firewall. Check for new VPN sessions from unusual geographies, lateral SMB/RDP activity, and persistence mechanisms on internal hosts.
- Review FortiGate configuration logs — specifically config changes, admin account creation/deletion events, and VPN login logs going back at least 90 days.
Strategic Hardening
- Implement a credential rotation policy for all firewall administrative accounts — no static shared credentials
- Deploy EDR or network detection capabilities that can identify post-compromise lateral movement originating from VPN gateways
- Ensure offline, encrypted backups of FortiGate configurations exist so devices can be rebuilt from a known-good state rather than a potentially tampered one
- Engage with threat intelligence feeds tracking FortiBleed-related IOCs — the attacker's backend was exposed once, meaning IOCs from that exposure remain valid for detection
The FortiBleed campaign illustrates a pattern we expect to see repeated: threat actors building operational infrastructure — scanning, credential validation, GPU cracking, target prioritization by revenue — that treats perimeter devices as a product to be harvested and sold. The ransomware affiliate model means initial access brokers are incentivized to compromise at scale. Defenders must respond at the same scale: every exposed management interface is a liability, and every legacy hash algorithm is an open door.