The FBI and U.S. Secret Service have reissued urgent warnings that FortiBleed, a large-scale credential harvesting campaign, continues to compromise Fortinet FortiGate firewalls and SSL VPN gateways that are exposed to the internet. The campaign is exploiting reused or leaked credentials, plus legacy SHA-256 password storage, to capture and crack authentication data across wide device populations.
What FortiBleed Is Doing & How It Operates
First identified in June 2026 by SOCRadar and Hudson Rock, FortiBleed has targeted thousands of Fortinet appliances worldwide. As of June 19, the operation has amassed more than 86,644 valid device credentials spanning 194 countries. Attackers use scans to probe internet-facing firewalls, then attempt logins using credentials from past leaks or infostealer logs.
Once access is achieved, a Go-based tool dubbed FortigateSniffer is deployed to passively intercept authentication traffic across 24 different protocols. Harvested password hashes are then offloaded to GPU-powered cracking clusters, using tools such as Hashmat and Hashtopolis for offline decryption. The compromised credentials are leveraged for lateral movement, Active Directory and Kerberos exploitation, SMB use, session cookie theft, and data exfiltration. Persistent access is maintained by creating new administrator accounts—and sometimes deleting or renaming original ones to prevent recovery.
Guidance & Immediate Risks
Authorities advise all Fortinet customers to take several measures immediately. These include enabling phishing-resistant authentication; ending active SSL VPN and admin sessions; resetting administrative and VPN passwords; using PBKDF2 (Password-Based Key Derivation Function 2) to store credentials; and closely reviewing logs for any indication of suspicious behavior.
Some compromised account names already identified include “adminin”, “fortiAdmin”, “admin”, “fgtsecure”, “forticloud-tech”, “support_fortinet”, among others. Intelligence suggests the operator may be an initial access broker selling access downstream—ties have been found connecting FortiBleed to INC and Lynx ransomware operations. Victims may also find themselves locked out entirely if attackers delete or alter their access credentials.
What To Do If You’re Affected
If compromise is suspected, organizations are told to isolate affected devices, preserve logs and artifacts, and report incidents to both the FBI and U.S. Secret Service. Alongside the technical mitigation steps listed earlier, swift action is needed to limit damage and prevent escalation.
FortiBleed is not just another hack—it’s a methodical, multi-stage campaign exploiting both human and technical weak points in device credential security. With more than 86,000 credentials stolen and scattered across nearly 200 countries, the scale makes this one of the most serious/hybrid threats to network perimeter security in recent memory.