FBI warns ongoing FortiBleed attacks target Fortinet VPNs and lock out administrators
United States federal agencies have warned that an ongoing credential harvesting campaign known as FortiBleed continues to compromise Fortinet devices and lock out system administrators.
FTMQ Security, written by our newsroom0 views

The Federal Bureau of Investigation and the Secret Service issued a warning that FortiBleed attacks are actively targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, according to reports from BleepingComputer, The Hacker News, and The Record. BleepingComputer and Cybersecurity Dive reported that the credential harvesting campaign is locking legitimate administrators out of their devices. [1][2][4][6]
The Hacker News reported that the campaign has targeted tens of thousands of devices, while CyberSecurityNews reported that more than 80,000 devices have been compromised. According to The Hacker News, federal authorities confirmed the campaign remains an active threat after amassing credentials from 86,644 Fortinet devices. [5][6]
According to BleepingComputer, hackers initial access begins by using previously leaked credentials, infostealer logs, credential stuffing, and password spraying attacks against exposed endpoints. Hackers then extract additional authentication data from compromised units and run offline cracking attempts against the stolen password hashes using Hashcat and Hashtopolis on distributed GPU clusters. [1]
Fortinet is an American cybersecurity company headquartered in Sunnyvale, California, that develops and sells security products including firewalls, endpoint security, and intrusion detection systems. [9]
In short
- The FBI and Secret Service warned that FortiBleed credential harvesting attacks are still ongoing.
- The campaign targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.
- Hackers have locked legitimate administrators out of their compromised Fortinet devices.
- Attackers use offline GPU clusters running Hashcat and Hashtopolis to crack stolen password hashes.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]FBI: Ongoing FortiBleed attacks lock out FortiGate VPN adminsBleepingComputer, 3h ago (the report this story comes from)
- [2]FBI warns that FortiBleed credential-harvesting attacks are locking out firewall usersCybersecurity Dive, 9h ago
- [3]FortiBleed still a bleeding nuisance as FBI confirms ongoing attacksThe Register, 14h ago
- [4]FBI, Secret Service add to warnings of FortiBleed credential stealing campaignThe Record from Recorded Future News, 11h ago
- [5]FBI Warns FortiBleed Attack Compromised 80,000+ Devices and Locked Out AdminsCyberSecurityNews, 11h ago
- [6]FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device CredentialsThe Hacker News, 13h ago
- [7]FortiBleed still a bleeding nuisance as FBI confirms ongoing attacksnews.lavx.hu, 8h ago
- [8]FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal CredentialsGBHackers News, 1d ago
Background
- [9]Fortinet on Wikipedia
Our newsroom writes these reports with the help of software, from the 9 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Microsoft Warns AI Compresses Attack Lifecycle from Days to MinutesData Breaches, 3d ago
More in Top Stories
- Attackers hijack top level domains to obtain unauthorized Google security certificates1h ago
- Discord security bot Double Counter breached exposing user email addresses1h ago
- MonsterCloud owner charged over secret ransomware payments1h ago
- Ransomware group BYOD claims data breach exposing Trump Mobile subscriber records1h ago
- FBI removes Accenture contractor following Oracle PeopleSoft data breach1d ago
- Fake AI Ad Portals Steal User Credentials and MFA Codes1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.