Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Hat Merz seine CDU noch im Griff? – POLITICO

    October 8, 2026

    Fuel prices added to Google Maps as petrol and diesel costs soar

    October 8, 2026

    Perplexity AI Releases pplx-embed-v2-late: A 0.6B Edge Model and a 9B Model Scoring 92.4% on MADQA

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Hat Merz seine CDU noch im Griff? – POLITICO
    • Fuel prices added to Google Maps as petrol and diesel costs soar
    • Perplexity AI Releases pplx-embed-v2-late: A 0.6B Edge Model and a 9B Model Scoring 92.4% on MADQA
    • Hackers hijack Google domains after breaching ccTLD registries
    • The Quantum Issue: Bitcoin Quantum Exposure At Block 950,000
    • Fighting Drought in Texas Cotton Country
    • Despite legacy court case, Zambian Vedanta mine pollution continues
    • Stockpile food – and wash your hands: is that really how to prepare for environmental catastrophe? | George Monbiot
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 07, 2026Cybercrime / Network Security

    The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.

    “The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale,” the agencies said. “Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials.”

    FortiBleed was first documented by SOCRadar in Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In all, the Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026.

    The campaign subsequently prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to urge Fortinet customers with FortiGate appliances to enable phishing-resistant authentication, terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrative passwords, use the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials, and review logs for signs of suspicious activity.

    FortiBleed is a five-stage campaign that conducts widespread reconnaissance to identify exposed portals, gain access to those devices using credential stuffing and password spraying based on data obtained from prior leak dumps and infostealer logs, and then deploy a Go-based tool called FortigateSniffer to passively intercept authentication traffic across 24 protocols and harvest credentials and password hashes.

    Cybersecurity

    The password hashes are then routed to a GPU-accelerated cracking cluster that uses Hashmat and Hashtopolis for offline cracking, after which they are used to facilitate lateral movement, Active Directory enumeration, Kerberos validation, and SMB authentication. In the final stage, sensitive data from network shares is exfiltrated while stolen session cookies are used to maintain persistent, authenticated access.

    “Cracked credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure,” the agencies said. “New administrative accounts were created on the firewall to maintain persistence.”

    With the verified credentials in hand, the attackers have been found to move deeper into victim environments, conduct enumeration, and conduct password spraying to expand access and identify privileged accounts.

    In addition, the initial access is used to add new accounts to the system as a way of maintaining persistence on the appliance. Some of the commonly identified compromised account names is listed below –

    • adminin
    • fortiAdmin
    • forticloud-sync
    • admin
    • fgtsecure
    • pakedge
    • forticloud-tech
    • districtadmin
    • system_config
    • gttadmin
    • roadmin
    • itadmin
    • Technical_support
    • adminsslvpn
    • IT_Manager
    • my_admin
    • support_fortinet
    • fgtsec
    • forti_support2

    The adversary is suspected to be an initial access broker that packages the stolen information and sells it to downstream threat actors. This is evidenced by the fact that operator overlaps tying FortiBleed to INC and Lynx ransomware operations, likely indicating that the access is being abused for ransomware deployment.

    Cybersecurity

    “Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system,” the FBI and USSS warned.

    “During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment.”

    If potential compromise is detected, organizations are advised to isolate the affected devices, collect necessary artifacts and logs, report the incident to the FBI and USSS, and apply relevant countermeasures to mitigate the threat.

    active Amassing Credentials Device FBI FortiBleed Fortinet remains warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers hijack Google domains after breaching ccTLD registries

    PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    IMF Chief Kristalina Georgieva Warns of Energy Shocks, Global Debt in 2027

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Hat Merz seine CDU noch im Griff? – POLITICO

    October 8, 2026

    Fuel prices added to Google Maps as petrol and diesel costs soar

    October 8, 2026

    Perplexity AI Releases pplx-embed-v2-late: A 0.6B Edge Model and a 9B Model Scoring 92.4% on MADQA

    October 8, 2026

    Hackers hijack Google domains after breaching ccTLD registries

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Hat Merz seine CDU noch im Griff? – POLITICO

    October 8, 2026

    Fuel prices added to Google Maps as petrol and diesel costs soar

    October 8, 2026

    Perplexity AI Releases pplx-embed-v2-late: A 0.6B Edge Model and a 9B Model Scoring 92.4% on MADQA

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.