US cybersecurity authorities have warned that the FortiBleed campaign has already breached 86,644 devices spanning 194 countries, according to a notice issued by the FBI and US Secret Service on October 6. The agencies cited figures from SOCRadar showing that attackers continue to actively scan internet-facing Fortinet firewalls using stolen login credentials. The campaign targets FortiGate firewalls and SSL VPN gateways, with ransomware groups from INC, Lynx, and Payload among those exploiting the compromised credentials for initial network access.

The attackers employ automated scanning tools to locate exposed FortiGate SSL VPN portals, then use credential stuffing and password spraying methods based on prior Fortinet breach dumps and infostealer logs. Once inside, they extract additional credentials and decrypt them using a GPU-accelerated cracking cluster running Hashcat and Hashtopolis software to convert passwords into plaintext. The stolen credentials are then sorted and validated through scripts that filter out honeypots, map organizations, and rank high-value targets by revenue and network structure. Attackers create new administrative accounts on firewalls to maintain persistent access, then move into victim environments to conduct Active Directory enumeration and password spraying to expand their reach and locate privileged accounts.

"Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials," the notice stated. Organizations could find themselves completely locked out of their own systems if threat actors disable accounts or alter passwords, requiring fixes that go beyond standard patching and password resets, the authorities warned. John Strand, owner of Black Hills Information Security, said the most worrying aspect of FortiBleed is the quiet persistence it provides to attackers: "I'm terrified of the attacker who wants to quietly live inside that organization for as long as possible."

The FortiBleed campaign was first exposed in June when a security researcher discovered a collection of Fortinet usernames and plaintext passwords. The FBI and Secret Service now urge organizations that detect potential compromise to isolate affected systems by quarantining or taking them offline, perform threat hunting to determine the scope of intrusion, and report incidents to federal authorities. The agencies recommend using CISA's Eviction Strategies Tool to remove threat actors, hardening networks by restricting management access, terminating all admin and VPN sessions while resetting credentials, and enabling phishing-resistant multi-factor authentication. Organizations should also review firewall and VPN users for unauthorized changes, examine logs for lateral movement across authentication systems and domain controllers, and ensure secure credential storage using the PBKDF2 algorithm. The distinction between noisy ransomware attacks and silent intrusions matters because adversaries who prioritize stealth over immediate impact can operate undetected for extended periods, fundamentally altering the risk calculus for security teams. Organizations running internet-facing infrastructure may need to reconsider whether the operational convenience of exposed management interfaces justifies the persistent targeting they invite.