The FBI Says a Fortinet Credential Harvesting Campaign Is Still Running Four Months After CISA's Guidance
Cybersecurity

The FBI Says a Fortinet Credential Harvesting Campaign Is Still Running Four Months After CISA's Guidance

The FBI and Secret Service warned on October 6 that FortiBleed, a campaign that has collected more than 86,644 Fortinet device credentials across 194 countries, remains active, despite CISA guidance issued back in June.

PublishedOctober 8, 2026
Read time5 min read
Share

What the FBI and Secret Service warned about

On Tuesday, October 6, the FBI and the US Secret Service issued a joint warning that FortiBleed, a Russian-speaking credential harvesting operation targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, remains active. The agencies describe the campaign as exploiting reused or leaked credentials combined with legacy SHA-256 password storage to harvest and crack authentication data at scale, and state plainly that attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials.

The scale is not new information so much as a reminder of how far this had already spread before the fresh warning. SOCRadar and Hudson Rock first documented the activity in June, estimating that the operation had obtained more than 86,644 working device credentials across 194 countries as of June 19. CISA issued remediation guidance to Fortinet customers that same month. The FBI's October alert exists because, four months later, the campaign has not stopped.

How the attack actually works

The campaign follows a disciplined pipeline. Operators first scan for exposed Fortinet portals, then gain initial access through credential stuffing and password spraying using leaked credential dumps and infostealer logs, the same reused-password problem that has fueled breaches for years. Once inside, they deploy a Go-based tool called FortigateSniffer that passively intercepts authentication traffic across 24 different protocols, capturing credentials as legitimate users and administrators log in normally. Because the interception is passive, legitimate logins continue to succeed and nothing about the user experience signals that anything is wrong, which is part of why the campaign has run undetected at this scale for months.

Captured hashes are then cracked offline on a GPU-accelerated cluster using Hashmat and Hashtopolis, after which operators move laterally, enumerate Active Directory, validate Kerberos tickets, and authenticate over SMB. The agencies report that attackers create new administrative accounts, using roughly 19 recurring names including admin, fortiAdmin, forticloud-sync, and support_fortinet, to maintain persistence, and in some cases delete existing accounts or change passwords, which locks out legitimate administrators and turns a quiet credential theft into an operational incident. From there, exfiltration of data from network shares follows, with stolen session cookies used to keep access alive even after a password reset, which is one reason remediation that stops at a password change has repeatedly failed to end the intrusion.

Why a four-month-old warning is news

The notable fact in this story is the gap between CISA's June guidance and the FBI's October follow-up. A joint FBI and Secret Service bulletin reiterating an active campaign four months after federal guidance already addressed it means one of two things: a meaningful number of organizations have not applied that guidance, or the guidance as applied has not actually closed the exposure. Either reading should concern a reader who assumed this was resolved months ago.

Operator overlaps that link FortiBleed to initial access brokers associated with INC and Lynx ransomware raise the stakes further. An initial access broker's business model is to harvest access and sell it forward, which means credentials captured in June may already have changed hands multiple times by October, each transfer putting the victim organization further from any realistic window for self-detection. A campaign that started as credential theft should now be modeled as a precursor to ransomware deployment for any organization that has not confirmed remediation.

What re-verification actually requires

CISA's June guidance called for enabling phishing-resistant authentication, terminating active SSL VPN and administrative sessions, resetting VPN and administrative passwords, storing administrator credentials with PBKDF2 instead of legacy SHA-256, and reviewing logs for suspicious activity. The FBI's October bulletin adds incident response guidance on top of that: isolate affected devices, collect artifacts and logs before making changes, report incidents to the FBI and Secret Service, and apply relevant countermeasures once the forensic picture is captured. Reading the two bulletins together, remediation and investigation are meant to happen in parallel, not as a single pass-through checklist.

The distinction that matters for a security leader is between having applied these steps once and having confirmed they held. A password reset performed in June does nothing if the device was already harvesting credentials at the time of reset and continued doing so afterward because FortigateSniffer was still deployed. Teams should specifically check for the unauthorized administrative account names the FBI lists, confirm PBKDF2 is actually in effect rather than just configured, and treat any Fortinet appliance that was internet-facing before June as requiring a fresh credential rotation now, not a review of whether the old one was done correctly.

The board-reporting angle

If your organization reported FortiBleed remediation as complete to the board or to a cyber insurance underwriter sometime after June, this warning is worth a direct follow-up communication, not a quiet internal recheck. A federal law enforcement bulletin restating that a previously reported-as-addressed campaign remains active is the kind of fact pattern that surfaces badly in hindsight if it surfaces at all, and surfacing it proactively costs far less credibility than having it surface during an incident.

More broadly, FortiBleed is a useful test case for how your organization tracks remediation status over time. A one-time patch confirmation is not the same control as an ongoing verification that the exposure has not reopened, especially against a campaign with a documented four-month-plus operational lifespan. Any edge device exposed to the internet, Fortinet or otherwise, deserves a recurring credential and configuration audit cadence rather than a single closed ticket, because this campaign has already proven that closing the ticket and closing the exposure are not the same event.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#fortinet#credential-harvesting#incident-response#fortibleed#fortigate#ssl-vpn#fbi-advisory#initial-access-broker