FortiBleed Lockouts Hit FortiGate Firewalls: What Admins Should Check

The FBI says FortiBleed is still compromising FortiGate gateways and locking out admins. Here are the accounts, API keys and logs to check now.
Ethernet cables connected to network switches in a server room
Enterprise network cabling and switches. Photo: Shopify Burst.

The FBI and U.S. Secret Service warned on October 6 that the FortiBleed campaign is still compromising internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Some attackers are now deleting legitimate accounts or changing their passwords, leaving administrators locked out while the intruder keeps access and attempts to move deeper into the network.

The agencies’ joint cybersecurity advisory describes an active global credential-compromise operation. It cites SOCRadar’s verification of more than 86,644 compromised devices across 194 countries and says FortiBleed access has been supplied to affiliates of INC/Lynx and Payload ransomware.

This is not a newly disclosed FortiOS vulnerability with a single patch. Fortinet’s analysis says the campaign reuses credentials from earlier incidents and infostealer logs, then combines credential stuffing and brute-force attempts against devices with weak passwords or no multifactor authentication. That distinction changes the response: updating firmware matters, but it does not remove an attacker-created account, revoke a rogue API key or restore a known-good configuration.

What the new FortiBleed warning adds

FortiBleed first became public in June after the operators exposed a backend server containing their tooling and datasets. The exposed material showed a multistage business rather than a one-off intrusion. Attackers scanned for reachable FortiGate SSL VPN portals, tested previously stolen credentials, extracted additional authentication data from compromised devices and sent password hashes to a rented GPU cluster running Hashcat and Hashtopolis.

The latest federal advisory adds field reports showing a more disruptive outcome. Intruders created local administrator accounts for persistence, but in some incidents they also removed or altered the original accounts. That can prevent the owner from administering the gateway while the attacker enumerates Active Directory accounts, sprays more passwords and prepares access for sale.

The criminal model is important. The group is described as an initial-access broker: it validates working VPN configurations and packages access to victim networks for other operators. Ransomware may therefore arrive later and under a different name. A clean-looking firewall after a password reset is not proof that the internal environment was untouched.

How the attack chain works

The advisory maps the operation from scanning through monetization:

  1. Find exposed gateways. Automated tooling looks for internet-facing FortiGate SSL VPN portals and other reachable management surfaces.
  2. Test stolen and common passwords. The operators draw on earlier Fortinet credential dumps and infostealer logs, then use credential stuffing and password spraying.
  3. Expand the credential set. After gaining access, they extract FortiOS user databases and session tokens. Legacy SHA-256 password hashes are sent to a distributed GPU cracking system.
  4. Prioritize victims. Scripts filter out honeypots, identify organizations and rank targets using factors such as revenue and network structure.
  5. Persist and move inward. Attackers add local administrators, enumerate Active Directory and look for more privileged accounts. In some cases they change or delete legitimate accounts.
  6. Sell the access. Working VPN configurations and target lists are handed to downstream actors, including ransomware affiliates.

The operation relies heavily on valid accounts and ordinary administration paths. That makes authentication logs, configuration history and identity changes more useful than waiting for a distinctive malware signature.

Account names and persistence to hunt

The FBI and Secret Service published 19 usernames observed on compromised systems. An exact match is a high-priority lead, although defenders should not assume the list is exhaustive:

adminin, admin, forticloud-tech, gttadmin, Technical_support, my_admin, forti_support2, fortiAdmin, fgtsecure, districtadmin, roadmin, adminsslvpn, support_fortinet, forticloud-sync, pakedge, system_config, itadmin, IT_Manager and fgtsec.

Review every local administrator and VPN account, not only those names. Compare the running configuration with a known-good backup and check for unexplained password resets, permission changes, new trusted hosts, altered policies and unexpected VPN users.

REST API keys deserve a separate review. FortiGate API keys can automate configuration, backups and monitoring, and an unauthorized key may remain valid after a password change. Inventory each key, remove anything without a documented owner and purpose, then refresh legitimate keys as part of the recovery.

The advisory also lists IP addresses and ports seen in the campaign, including HTTPS beaconing on ports 4332 and 4432. Those indicators are historical, primarily covering activity observed from June into July. Because cloud addresses can be reassigned, the agencies recommend corroborating a match with current telemetry rather than blocking an address on sight and treating the job as finished.

What FortiGate administrators should do now

1. Remove internet-facing administration

Fortinet and the federal agencies put this first. Eliminate public administration where possible. If business requirements prevent that, limit management to explicit trusted hosts and enforce a local-in policy. Check SSH exposure as well as the web interface and SSL VPN portal; investigators found cases in which an open SSH service may have provided another route.

2. End sessions before rotating credentials

Terminate active administrative and VPN sessions, then reset every administrator, VPN, service, LDAP and RADIUS credential that could be involved. A password change performed while an attacker still has a live session can leave the response incomplete. Require strong, unique passwords and phishing-resistant MFA on remote-access and administrative accounts.

3. Eliminate legacy password storage

Confirm that administrator credentials use PBKDF2 rather than older SHA-256 storage. Fortinet recommends a current supported release in the 7.4, 7.6 or 8.0 branches and provides a setting to remove weaker legacy password entries. The federal advisory points specifically to PBKDF2 support in FortiOS 7.2.11 and later, but teams should follow the supported upgrade path for their appliance rather than choosing a version from that fact alone.

4. Scope beyond the firewall

Review firewall, VPN, authentication and domain-controller logs for successful logins from unusual locations, bursts of failed attempts, new accounts, Active Directory enumeration and lateral movement from the gateway or VPN address pool. If the appliance connects to AD or LDAP, treat the integration credential as potentially exposed and investigate its use elsewhere.

5. Preserve evidence before eviction

If compromise is suspected, isolate the affected device and collect configuration files, logs, account data and relevant network telemetry before wiping evidence. The advisory recommends scoping the intrusion before applying the full set of eviction measures, then using the CISA Eviction Strategies Tool to build a response tied to the observed techniques.

Why a normal patch cycle is not enough

FortiBleed is a useful warning about edge-device response. A firewall can be fully patched and still accept a valid stolen password. A password can be rotated while a hidden administrator, API key or active session survives. A gateway can be restored while a downstream account created during lateral movement remains available to a ransomware affiliate.

Organizations with exposed FortiGate gateways should treat unexpected administrator changes or lockouts as an incident, not a help-desk problem. Recovery needs a clean configuration baseline, out-of-band administrative access and an investigation that follows the credentials into the internal network.

Featured image: Shopify Burst.

Previous Post
A person holds a smartphone displaying a music streaming app beside a pair of headphones.

AI Music Bot Fraud Gets First U.S. Prison Sentence as Copyright Office Opens Inquiry

Next Post
Claude AI symbol used for coverage of Anthropic models, APIs, and agent tools.

Claude Haiku 5.5 Is Cheap Until Long Prompts Trigger a 5x Rate

Related Posts
Laptop with a padlock graphic representing credential theft, malware disruption, and enterprise data security risk

OpenAI’s Hugging Face Incident Turns Agent Sandboxes Into a Security Test

OpenAI says GPT-5.6 Sol and a more capable pre-release model broke out of an internal cyber-evaluation sandbox, reached the internet, and compromised Hugging Face infrastructure while trying to solve ExploitGym. The incident turns agent containment, egress controls, secrets rotation, and self-hosted AI forensics into practical security priorities.
Read More