Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Polls open in Holborn and St Pancras byelection – UK politics live | Politics

    October 8, 2026

    ChatGPT for Teens keeps teens talking, even during mental health crises

    October 8, 2026

    We are fighting phishing at the wrong layer

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Polls open in Holborn and St Pancras byelection – UK politics live | Politics
    • ChatGPT for Teens keeps teens talking, even during mental health crises
    • We are fighting phishing at the wrong layer
    • Samsung taps Solana and Sui to launch zero-fee USDC global remittances on 82 million phones
    • Stanford scientists turn a cancer driver into a kill switch
    • Colombia’s new government backs fracking as debate over energy future heats up
    • French minister invites UK to ‘come all the way back’ to the EU | Brexit
    • India rejects Elon Musk’s claim of discrimination over Starlink launch
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    FortiBleed Attackers Locking Victims Out of Fortinet Devices

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The FortiBleed credential-harvesting and access-broker campaign is still active, and attackers are locking organizations out of their Fortinet devices.

    Targeting internet-accessible Fortinet FortiGate firewalls and SSL VPN appliances, the campaign started in June.

    Fortinet’s analysis of the attacks revealed that the attackers were using previously compromised credentials and brute-force techniques to take over poorly protected devices.

    Within a week, the attacks hit over 86,000 Fortinet devices in 190 countries, and a Russian initial access broker was blamed for the campaign.

    Now, SOCRadar says it has confirmed the compromise of approximately 86,644 devices in 194 countries. The attackers are searching for accessible firewalls and using compromised credentials to take them over.

    “[This] is a count of confirmed-compromised devices, not an exposure estimate. Devices breached months ago remain in the actors’ validated inventory,” SOCRadar notes.

    Advertisement. Scroll to continue reading.

    In a joint advisory (PDF) released this week, the FBI and the US Secret Service (USSS) warn that the hackers have been locking organizations out of their Fortinet appliances by changing passwords and deleting accounts.

    “Some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment,” the advisory reads.

    The hackers have been observed scanning for exposed SSL VPN portals, harvesting credentials from infostealer logs and previous dumps, cracking hashed credentials offline, mapping the attack surface to evade honeypots, using verified credentials to compromise devices, and selling working VPN configs and target lists to other threat actors.

    The FBI and USSS recommend that affected organizations identify the compromised hosts, scope the intrusion, evict the attackers, harden protections to prevent additional threat actor activity, and report the intrusions.

    To reduce the attack surface, organizations should restrict management access, reset all Fortinet VPN and administrative passwords, implement phishing-resistant multifactor authentication (MFA), review firewall and VPN users and configurations, review and validate API keys, review logs for suspicious activity, and ensure credentials are stored securely.

    Related: Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

    Related: Anthropic Introduces 3-Tier Cyber Verification Program for AI Access

    Related: Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies

    Related: FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

    Attackers devices FortiBleed Fortinet locking Victims
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    We are fighting phishing at the wrong layer

    Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

    Hackers hijack Google domains after breaching ccTLD registries

    FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

    PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Polls open in Holborn and St Pancras byelection – UK politics live | Politics

    October 8, 2026

    ChatGPT for Teens keeps teens talking, even during mental health crises

    October 8, 2026

    We are fighting phishing at the wrong layer

    October 8, 2026

    Samsung taps Solana and Sui to launch zero-fee USDC global remittances on 82 million phones

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Polls open in Holborn and St Pancras byelection – UK politics live | Politics

    October 8, 2026

    ChatGPT for Teens keeps teens talking, even during mental health crises

    October 8, 2026

    We are fighting phishing at the wrong layer

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.