What's Happening?
The FBI and U.S. Secret Service have issued a joint advisory warning that FortiBleed attacks are continuing to compromise Fortinet devices, with over 86,644 devices affected across 194 countries. These attacks primarily target internet-facing FortiGate
firewalls and SSL VPN gateways. Fortinet has clarified that the activity involves the reuse of previously stolen credentials and brute-force attacks, rather than a newly discovered vulnerability. Attackers are scanning exposed FortiGate VPN portals, testing credentials from past data leaks and infostealer logs, and exploiting legacy SHA-256 password storage to crack password hashes offline. Once unauthorized access is gained, intruders can create new administrator accounts, investigate Active Directory, and attempt to access other systems. In some instances, attackers have locked legitimate administrators out of their devices by changing or deleting their accounts while retaining their own access. The advisory emphasizes that simply patching devices may not be sufficient if attackers have already established a foothold within the network.
Why It's Important?
This ongoing threat poses a significant risk to U.S. organizations, particularly those relying on Fortinet's widely used security products. The compromise of over 86,000 devices globally indicates a widespread vulnerability that could lead to substantial data breaches, operational disruptions, and financial losses for affected entities. The FBI and Secret Service's warning highlights the critical importance of comprehensive cybersecurity practices beyond just applying patches. The fact that attackers are leveraging previously stolen credentials and brute-force methods underscores the need for strong password policies, multi-factor authentication (MFA), and regular auditing of user accounts and access logs. The reported link between FortiBleed-derived access and ransomware deployments, with at least 12 confirmed ransomware incidents and hundreds of encrypted endpoints, demonstrates the severe real-world consequences of these attacks. This situation also brings to light the challenges of securing branch-office appliances and third-party-managed devices, which may be overlooked in routine security assessments, creating potential entry points for adversaries.
What's Next?
The FBI and Secret Service recommend immediate and thorough actions for organizations using FortiGate firewalls and SSL VPNs, even if they have already applied patches. These steps include inventorying all internet-facing FortiGate management interfaces and VPN gateways, including those in branch locations, and restricting public administrative access where possible. Organizations must terminate unauthorized administrator and VPN sessions, reset passwords, and enforce phishing-resistant MFA. A critical step is to verify administrator accounts and API keys, removing any unauthorized ones and refreshing legitimate keys. Furthermore, security teams are advised to investigate historical activity by comparing configurations with known-good versions and examining firewall, VPN, authentication, and domain-controller logs for any suspicious access or lateral movement. Fortinet's version-specific guidance should be followed to ensure administrator passwords use PBKDF2 and to remove retained legacy SHA-256 hashes, as a firmware upgrade alone does not complete this process. If signs of compromise are found, isolating affected systems, preserving evidence, and planning for attacker removal are crucial next steps.
Beyond the Headlines
The FortiBleed attacks underscore a deeper, systemic challenge in cybersecurity: the persistent threat of credential compromise and the need for a 'assume breach' mentality. Even with robust security measures and timely patching, attackers can maintain access if they have stolen valid credentials or created unauthorized accounts. This situation highlights the importance of continuous monitoring, threat hunting, and incident response capabilities. The exploitation of legacy SHA-256 password storage also points to the need for organizations to regularly review and update their cryptographic standards for password hashing. The involvement of access brokers and ransomware affiliates in leveraging FortiBleed access signifies the professionalization and interconnectedness of cybercrime ecosystems. This incident serves as a stark reminder that cybersecurity is not a one-time fix but an ongoing process requiring vigilance, proactive measures, and a holistic approach that encompasses technology, processes, and people. The ethical implications of compromised credentials extend to potential privacy violations and the erosion of trust in digital systems, necessitating a stronger collective defense against such sophisticated threats.













