Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Fighting Drought in Texas Cotton Country

    October 8, 2026

    Despite legacy court case, Zambian Vedanta mine pollution continues

    October 8, 2026

    Stockpile food – and wash your hands: is that really how to prepare for environmental catastrophe? | George Monbiot

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Fighting Drought in Texas Cotton Country
    • Despite legacy court case, Zambian Vedanta mine pollution continues
    • Stockpile food – and wash your hands: is that really how to prepare for environmental catastrophe? | George Monbiot
    • Three people killed in attacks on Saudi Arabia airports, officials say
    • ‘I feel perfectly safe’: white Lutonians on the town’s supposed no-go zones | Luton
    • AI chip boom pushes Samsung profits to record $80bn
    • Anthropic Releases Claude Haiku 5.5: A Small Model With 1M Context Priced at $0.10 per Million Input Tokens
    • FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 07, 2026Cybercrime / Network Security

    The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.

    “The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale,” the agencies said. “Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials.”

    FortiBleed was first documented by SOCRadar in Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In all, the Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026.

    The campaign subsequently prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to urge Fortinet customers with FortiGate appliances to enable phishing-resistant authentication, terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrative passwords, use the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials, and review logs for signs of suspicious activity.

    FortiBleed is a five-stage campaign that conducts widespread reconnaissance to identify exposed portals, gain access to those devices using credential stuffing and password spraying based on data obtained from prior leak dumps and infostealer logs, and then deploy a Go-based tool called FortigateSniffer to passively intercept authentication traffic across 24 protocols and harvest credentials and password hashes.

    Cybersecurity

    The password hashes are then routed to a GPU-accelerated cracking cluster that uses Hashmat and Hashtopolis for offline cracking, after which they are used to facilitate lateral movement, Active Directory enumeration, Kerberos validation, and SMB authentication. In the final stage, sensitive data from network shares is exfiltrated while stolen session cookies are used to maintain persistent, authenticated access.

    “Cracked credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure,” the agencies said. “New administrative accounts were created on the firewall to maintain persistence.”

    With the verified credentials in hand, the attackers have been found to move deeper into victim environments, conduct enumeration, and conduct password spraying to expand access and identify privileged accounts.

    In addition, the initial access is used to add new accounts to the system as a way of maintaining persistence on the appliance. Some of the commonly identified compromised account names is listed below –

    • adminin
    • fortiAdmin
    • forticloud-sync
    • admin
    • fgtsecure
    • pakedge
    • forticloud-tech
    • districtadmin
    • system_config
    • gttadmin
    • roadmin
    • itadmin
    • Technical_support
    • adminsslvpn
    • IT_Manager
    • my_admin
    • support_fortinet
    • fgtsec
    • forti_support2

    The adversary is suspected to be an initial access broker that packages the stolen information and sells it to downstream threat actors. This is evidenced by the fact that operator overlaps tying FortiBleed to INC and Lynx ransomware operations, likely indicating that the access is being abused for ransomware deployment.

    Cybersecurity

    “Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system,” the FBI and USSS warned.

    “During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment.”

    If potential compromise is detected, organizations are advised to isolate the affected devices, collect necessary artifacts and logs, report the incident to the FBI and USSS, and apply relevant countermeasures to mitigate the threat.

    active Amassing Credentials Device FBI FortiBleed Fortinet remains warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    IMF Chief Kristalina Georgieva Warns of Energy Shocks, Global Debt in 2027

    Ransomware recovery CEO charged over secret ransom payments

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Fighting Drought in Texas Cotton Country

    October 8, 2026

    Despite legacy court case, Zambian Vedanta mine pollution continues

    October 8, 2026

    Stockpile food – and wash your hands: is that really how to prepare for environmental catastrophe? | George Monbiot

    October 8, 2026

    Three people killed in attacks on Saudi Arabia airports, officials say

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Fighting Drought in Texas Cotton Country

    October 8, 2026

    Despite legacy court case, Zambian Vedanta mine pollution continues

    October 8, 2026

    Stockpile food – and wash your hands: is that really how to prepare for environmental catastrophe? | George Monbiot

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.