Executive Summary
The FBI and Secret Service issued warnings in October 2026 that the FortiBleed credential harvesting campaign continues targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. This Russian-speaking operation has successfully compromised over 86,644 device credentials across 194 countries using a sophisticated five-stage attack chain involving credential stuffing, passive traffic interception, GPU-accelerated password cracking, and lateral movement. The campaign exploits reused credentials and legacy SHA-256 password storage, with attackers creating persistent backdoor accounts and selling access to ransomware groups including INC and Lynx operators.
This incident highlights the escalating threat to network perimeter devices as initial access brokers increasingly target enterprise VPN infrastructure to enable downstream ransomware operations, making credential security and multi-factor authentication critical defensive priorities.
Why This Matters Now
FortiBleed represents a paradigm shift toward industrialized credential harvesting at unprecedented scale, with threat actors weaponizing GPU clusters and automated tooling to crack credentials faster than organizations can rotate them, making traditional password-based authentication insufficient for protecting critical network infrastructure.
Attack Path Analysis
FortiBleed attackers conducted widespread reconnaissance to identify exposed Fortinet FortiGate firewalls, then used credential stuffing and password spraying from leaked credentials to gain initial access. Once authenticated, they deployed FortigateSniffer to harvest credentials across 24 protocols, created persistent admin accounts, and conducted Active Directory enumeration for privilege escalation. The attackers performed lateral movement through SMB authentication and Kerberos validation using cracked credentials. They established command and control through persistent authenticated sessions using stolen session cookies. Sensitive data was exfiltrated from network shares while maintaining access through newly created administrative accounts. The campaign serves as an initial access brokerage operation, with stolen access being sold to ransomware groups including INC and Lynx for final impact deployment.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers conducted reconnaissance to identify internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, then used credential stuffing and password spraying attacks with previously compromised credentials from leak dumps and infostealer logs to gain authenticated access
MITRE ATT&CK® Techniques
Valid Accounts
Brute Force: Credential Stuffing
Brute Force: Password Spraying
Network Sniffing
Create Account: Local Account
Account Discovery: Domain Account
Data from Network Shared Drive
Remote Services: SMB/Windows Admin Shares
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography for Authentication Data Storage
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Identity and Credential Management
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Password Management System
Control ID: A.9.4.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
FortiBleed credential harvesting targeting Fortinet VPN gateways creates critical breach risks for financial institutions requiring HIPAA/PCI compliance and encrypted traffic protection.
Health Care / Life Sciences
Healthcare networks face severe HIPAA violation risks from FortiBleed's credential stuffing attacks on SSL VPN gateways, enabling lateral movement and patient data exfiltration.
Government Administration
Government agencies using Fortinet firewalls are prime targets for FortiBleed's credential harvesting, with 86,644 compromised devices creating national security implications globally.
Information Technology/IT
IT service providers managing Fortinet infrastructure face cascading client breaches from FortiBleed's five-stage attack enabling ransomware deployment and persistent administrative access.
Sources
- FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentialshttps://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.htmlVerified
- FBI and USSS Joint Cybersecurity Advisory on FortiBleed Campaignhttps://www.ic3.gov/CSA/2026/261006.pdfVerified
- CISA Warning to Fortinet Customers on FortiBleed Campaignhttps://www.cisa.gov/news-events/alerts/2026/06/20/fortibleed-campaign-targeting-fortinet-devicesVerified
- SOCRadar FortiBleed Campaign Analysishttps://socradar.io/fortibleed-massive-credential-harvesting-campaign-targeting-fortinet-devices/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained FortiBleed attackers' ability to move laterally and access sensitive resources through network segmentation and identity-aware access controls. The attack's blast radius would likely be significantly reduced through workload isolation and controlled east-west traffic flows.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial access to perimeter devices would likely remain possible, but attackers' subsequent reach into cloud workloads and internal network segments would be significantly constrained through identity-aware routing and segmented network policies
Control: Zero Trust Segmentation
Mitigation: While credential harvesting from compromised perimeter devices may still occur, attackers' ability to leverage those credentials for privileged access to segmented workloads and cloud resources would likely be constrained through identity-scoped network policies
Control: East-West Traffic Security
Mitigation: Cracked credentials would likely provide limited lateral movement capability as east-west traffic enforcement would constrain SMB and authentication flows between segmented workloads, reducing the attackers' ability to traverse the internal network freely
Control: Multicloud Visibility & Control
Mitigation: While perimeter device compromise may persist, attackers' command and control reach into cloud workloads and cross-cloud environments would likely be constrained through centralized visibility and policy enforcement that monitors and restricts unauthorized communications
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration volumes and destinations would likely be constrained through controlled egress policies that monitor and restrict outbound data flows, limiting attackers' ability to systematically extract large datasets from cloud workloads and network shares
Ransomware impact would likely be constrained to legacy infrastructure and assets outside zero trust segmentation, with cloud workloads and properly segmented network resources maintaining operational capability and reduced exposure to encryption attacks
Impact at a Glance
Affected Business Functions
- Network Security Infrastructure
- SSL VPN Remote Access
- Firewall Protection Services
- Administrative Network Management
Estimated downtime: 7 days
Estimated loss: N/A
Over 86,644 Fortinet device credentials compromised across 194 countries, including administrative passwords, SSL VPN credentials, password hashes, session cookies, and authentication data across 24 protocols. Stolen credentials used for lateral movement, Active Directory enumeration, and potential access to sensitive network shares and internal systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with identity-based policies to prevent lateral movement even after initial firewall compromise
- • Deploy egress security controls with FQDN filtering to detect and block unauthorized data exfiltration from network shares
- • Enable multicloud visibility and anomaly detection to identify suspicious authentication patterns and credential harvesting activities
- • Establish east-west traffic security monitoring to detect SMB authentication abuse and Kerberos validation attacks during lateral movement
- • Implement threat detection capabilities with baseline anomaly analysis to identify persistent administrative account creation and session cookie abuse



