Advisory
Published 2026-10-06
Verified 2026-10-07

FBI and US Secret Service joint advisory (6 Oct): the FortiBleed credential campaign against FortiGate firewalls and SSL VPNs is still active, with attackers creating their own admin accounts and locking owners out; access is sold on to ransomware crews

The FBI and the US Secret Service published joint cybersecurity advisory JCSA-20261006-01 on 6 October 2026, warning that FortiBleed is an active, worldwide campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. FortiBleed is not a single new software bug: the operators use credential stuffing and password spraying with logins from earlier Fortinet leak dumps and infostealer logs, then take password hashes from devices that still store administrator passwords with legacy SHA-256 and crack them offline on a GPU cluster run with Hashcat and Hashtopolis. SOCRadar has verified more than 86,644 compromised devices in 194 countries. The workflow came to light because the operators left their own backend server open; it shows them filtering out honeypots, ranking victims by revenue and network layout, creating new administrator accounts on the firewall to keep access, enumerating Active Directory and spraying passwords inside the network, then selling working VPN access. The agencies say some victims have been locked out after the attackers deleted or changed the original admin accounts, so recovery can take more than a patch and a password reset, and that the access has been used as an entry point for ransomware affiliates (wire reports name INC/Lynx and Payload). The advisory lists account names seen on victim devices, including forticloud-sync, forticloud-tech, fortiAdmin, adminin, districtadmin and system_config, and infrastructure including a command-and-control server at 45.154.12[.]132 and a Hashtopolis host at 85.11.187[.]8. Primary: FBI/USSS joint advisory on IC3; wires: The Hacker News and Cyber Security News (7 Oct).

Product
Fortinet FortiGate firewalls and FortiOS SSL VPN gateways exposed to the internet
Versions
n/a — credential abuse, not a single CVE; devices storing admin passwords with legacy SHA-256 are most at risk
Exploited in Australia?
unknown
Patch to
Take FortiGate administration off the internet (trusted hosts at minimum, a local-in policy is better, no internet admin is best). End all active admin and VPN sessions, reset every Fortinet VPN and administrator password, and require phishing-resistant MFA on remote access and admin interfaces. Make sure FortiOS stores admin credentials with PBKDF2. Review every account on the device against the advisory's list of attacker-created names, check for unexpected REST API keys and config changes, block the listed IP addresses, and review firewall, VPN and domain-controller logs for logins and lateral movement you cannot explain.

Primary: FBI and USSS — Joint Cybersecurity Advisory JCSA-20261006-01: FortiBleed operations continue targeting exposed systems leading to reports of lockouts (6 Oct 2026, PDF) · Vendor: The Hacker News — FBI warns FortiBleed remains active after amassing 86,644 Fortinet device credentials (7 Oct 2026) · Cyber Security News — FortiBleed attack campaign exploiting Fortinet firewalls and VPNs, FBI warns (7 Oct 2026)

vulnerabilities network identity