News

FBI Says FortiBleed Hackers Are Locking Owners Out of Their Own Firewalls and Feeding Ransomware Gangs

No zero-day required. A campaign built on stolen and reused passwords has taken over tens of thousands of Fortinet firewalls, and the FBI says some owners can no longer get back into their own gear.

FBI Says FortiBleed Hackers Are Locking Owners Out of Their Own Firewalls and Feeding Ransomware Gangs

The device that is supposed to keep attackers out of the network is now the thing locking its owners out. The FBI and the US Secret Service warned on Tuesday that FortiBleed, a credential theft campaign aimed at internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is still active and still feeding ransomware crews.

"Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets," the joint alert says.

No bug, just bad passwords

FortiBleed doesn't exploit a software flaw. The attackers get in with credentials that were already floating around: passwords reused from old breaches and harvested from infostealer logs, tried at scale through credential stuffing and password spraying.

Once inside a device, they get more methodical. According to the attack chain laid out in the alert, they drop a Go tool called FortigateSniffer that quietly intercepts authentication traffic across 24 protocols. They also pull password hashes, which legacy SHA-256 storage leaves weak enough to crack offline on GPU clusters.

Then they dig in. The intruders create fresh admin accounts for persistence and, in some cases, delete or change the original accounts, so the legitimate owners can't log in to their own firewall.

Access for sale

The operation, run by a Russian-speaking group suspected of being an initial access broker, was first documented by SOCRadar in June. The firm verified more than 86,644 compromised devices across 194 countries.

That count turned out to be the floor. SOCRadar CISO Ensar Seker told CyberScoop that later investigation found "more than 400,000 or 450,000 firewalls targeted by the wider operation," and that the numbers "show the campaign is broader and more serious than we understood at the beginning."

The stolen access is a product. Cracked credentials were sorted to weed out honeypots and rank victims by revenue, then sold to affiliates of the INC/Lynx and Payload ransomware groups. By July, SOCRadar had tied at least 12 confirmed ransomware attacks to FortiBleed, and the federal alert now says "the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates."

The edge keeps bleeding

Fortinet owners have had a rough stretch. Last week the company warned about a FortiMail zero-day under active exploitation, an actual unpatched flaw, and SonicWall customers are dealing with SMA 1000 zero-days under attack. FortiBleed is a reminder that attackers going after edge gateways don't always need a new bug when an old password will do.

The agencies want organizations to pull management interfaces off the internet where they can, kill active admin and VPN sessions, reset passwords, move to phishing-resistant MFA, switch admin credential storage to PBKDF2, and review logs for signs of lateral movement. They also told victims not to pay ransoms and asked them to share indicators, including IP addresses and the usernames the attackers create.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free