FortiBleed FBI Advisory: Admin Lockouts and New IoCs
Four months after FortiBleed first surfaced, the FBI and the U.S. Secret Service say the campaign has not stopped. Attackers are still logging in to exposed FortiGate firewalls with stolen passwords, and in some cases they are now deleting or resetting the real administrator accounts so the owners cannot get back in. There is no patch for this, because there is no bug. The fix is credential hygiene, and a lookback window long enough to reach June.
What: FortiBleed, a credential-harvesting and access-brokering campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Joint FBI and USSS advisory JCSA-20261006-01, dated October 6, 2026.
Status: Ongoing. The advisory reports admin lockouts and says the chain has served as an entry point for ransomware affiliates. No CVE is referenced.
Deadline: None. With no CVE, there is no CISA KEV entry or federal due date. Treat exposed FortiGate management and VPN portals as an open incident until you have checked them.
Fix: No firmware patch closes this. End all admin and VPN sessions, reset every Fortinet admin and VPN password, enforce phishing-resistant MFA, store admin credentials with PBKDF2, and hunt for the advisory’s account names and IPs.
Key takeaways
- FortiBleed is still active as of October 2026. The FBI and Secret Service say attackers keep scanning exposed FortiGate firewalls and logging in with credentials obtained earlier.
- The new behavior is lockout. Intruders add their own admin accounts, then delete or reset the legitimate ones, which blocks the owner and protects the attacker’s foothold.
- The advisory publishes concrete IoCs: 20 IP addresses, beacon ports 4332 and 4432, and 19 account names such as
forticloud-syncandsupport_fortinet. - Password resets alone are not enough. The campaign cracks legacy SHA-256 hashes offline, so the advisory pairs resets with PBKDF2 storage and phishing-resistant MFA.
- Most of the published login IPs were seen between June 18 and July 23, 2026. If your log retention is 90 days, part of that window is already gone.
Executive Summary
FortiBleed was never a one-week story. Federal investigators now say it is still producing victims.
DataWater first covered the FortiBleed credential exposure in June, and followed up when CISA issued guidance and the count reached 86,644 devices. On October 6, the FBI and the U.S. Secret Service released a joint advisory, JCSA-20261006-01, titled around continued FortiBleed operations and reports of lockouts. It publishes a concrete set of indicators: attacker infrastructure, IPs seen logging in with compromised accounts, and the account names attackers left behind.
The advisory describes an industrialized workflow. Scripts find reachable FortiGate SSL VPN portals. Leaked passwords and infostealer logs are sprayed against them. Password hashes taken from compromised devices are cracked on a rented GPU cluster with Hashcat and Hashtopolis. Valid access is filtered to weed out honeypots, ranked by the victim’s revenue and network layout, then packaged with working VPN configurations and sold. The FBI says ransomware affiliates, including INC/Lynx and Payload, have used this chain as a way in.
The bottom line: if you run an internet-facing FortiGate, check it today for the account names in this advisory, confirm your own admins can still log in, and make sure the credentials you reset are not stored in a format the attacker can crack again.
Why This Matters to CISOs and Security Leaders
This is a vulnerability program blind spot. Most edge-device programs are driven by CVEs and KEV deadlines. FortiBleed has neither. A FortiGate can be fully patched and still be owned by someone holding a valid admin password. If your dashboards only track firmware versions, they will show green on a compromised firewall.
Lockout changes the response playbook. When attackers delete or reset the real admin accounts, the first sign may be a network engineer who suddenly cannot log in. Teams need a pre-agreed path for that: out-of-band console access, a vendor support route, and a rule that a failed admin login on an edge device is escalated to security, not just to the help desk.
Edge devices remain the front door. FortiBleed sits alongside the exploited FortiMail zero-day CVE-2026-104286 and the NetScaler SAML zero-day CVE-2026-88779 on many teams’ edge-device lists this month. The difference is that this one is about identity, not code.
Ask your network team two questions this week: “Which local admin accounts exist on each FortiGate right now, and who created each one?” and “Are our FortiGate admin passwords stored with PBKDF2?” If either answer takes more than a day to produce, that gap is your FortiBleed exposure.
The Timeline
| Date (2026) | What happened |
|---|---|
| June | The operators inadvertently expose a server holding harvested Fortinet credentials. One report says the June leak tied usernames and plaintext passwords to 73,932 firewall URLs in 194 countries (single-source figure). |
| June 18 | Earliest date on the advisory’s list of IPs seen brute-forcing or logging in with compromised accounts |
| June 19 | Tally of affected Fortinet devices reaches 86,644 across 194 countries, the figure SOCRadar has since verified |
| June | CISA issues guidance to Fortinet customers: end sessions, reset passwords, use phishing-resistant MFA and PBKDF2 |
| July | SOCRadar links FortiBleed to INC and Lynx ransomware after gaining access to negotiation panels on a campaign server, according to one report |
| July 23 | Latest date on the advisory’s list of malicious login IPs |
| Later (date unknown) | The operators expose a backend directory of scanning, cracking, honeypot-filtering and target-ranking tooling, plus VPN configurations and target lists |
| Tuesday, Oct 6 | FBI and USSS publish joint advisory JCSA-20261006-01 warning of continued operations and admin lockouts |
| Oct 7–8 | The Hacker News, BleepingComputer, Help Net Security and SecurityWeek report the advisory |
A firewall on the latest firmware can still belong to someone else. FortiBleed never needed a bug, only a password.
Vulnerability & Exploit Analysis
No CVE, and that is the point
The FBI/USSS advisory does not reference any CVE. FortiBleed works through credential stuffing, password spraying with previously leaked data, and offline cracking of password hashes pulled from devices that were already breached. The advisory’s MITRE ATT&CK mapping does list “Exploit Public-Facing Application,” but in the context of targeting exposed FortiGate infrastructure, not a named software flaw. Fortinet’s own analysis, as reported by SecurityWeek, also points to previously compromised credentials and brute force against poorly protected devices.
The weak link: legacy SHA-256 password storage
The advisory says the campaign takes advantage of legacy SHA-256 storage of admin passwords, which is far easier to crack offline than PBKDF2. Its guidance is to store administrator credentials with PBKDF2 and remove legacy hashes, following Fortinet’s guidance for FortiOS 7.2.11 and later. A reset on a device that still writes SHA-256 hashes gives an attacker who returns a fresh hash to crack.
| Device condition | FortiBleed risk | What to do |
|---|---|---|
| Admin GUI or SSL VPN portal reachable from the internet | High | Restrict management to trusted hosts or a local-in policy; best is no internet-facing admin at all |
| Admin passwords stored as legacy SHA-256 | High | Move to PBKDF2 per Fortinet guidance (FortiOS 7.2.11 and later), then reset |
| Password-only VPN or admin login | High | Enforce phishing-resistant MFA on all remote access and admin accounts |
| Unknown or unreviewed REST API keys | Elevated | Remove unknown keys and rotate legitimate ones |
| SSH open to the internet | Elevated | Close it; the advisory says SSH may have been abused where the port was open |
What happens after login
According to the advisory, attackers create new admin accounts for persistence, pull FortiOS user databases, session tokens and hashes, then use working credentials to enumerate Active Directory and spray passwords internally. One report adds that a Go-based tool called FortigateSniffer was used to capture authentication traffic across 24 protocols, and that stolen session cookies were reused for persistent access (single-source).
The advisory came out on October 6, but nearly all of its login IPs were seen between June 18 and July 23. June 18 is now more than 110 days ago. Many firewall and SIEM deployments keep 90 days of logs, so the evidence that would show whether those IPs touched your devices may already have aged out. If that is your situation, the account-name list and a full config review are your best remaining evidence, and you should extend retention for edge devices before the next campaign.
Threat Intelligence Breakdown
Attribution: The FBI/USSS advisory does not name a specific actor. The Hacker News describes the operation as Russian-speaking and suspects an initial access broker; SecurityWeek reports that a Russian initial access broker has been blamed. The advisory itself names INC/Lynx and Payload ransomware affiliates as users of the access chain. Victim totals beyond the 86,644 device figure are unknown.
How the count is framed: SOCRadar describes 86,644 as confirmed-compromised devices in 194 countries, not an exposure estimate, and notes that devices breached months ago remain in the attackers’ validated inventory. One outlet describes the same figure as working device credentials.
Indicators of compromise (FBI/USSS advisory JCSA-20261006-01, defanged). The advisory warns that cloud-hosted IPs may since have been reassigned to benign services, so check them against current telemetry before blocking.
| Type | Indicator | Context |
|---|---|---|
| IP address | 45.154.12[.]132 | Command-and-control server |
| IP address | 154.202.59[.]169 | Proxy node |
| IP address | 103.27.186[.]156 | Proxy node |
| IP address | 45.155.250[.]158 | Beacon relay |
| IP address | 193.8.187[.]2, 193.8.187[.]42 | Attack chain infrastructure |
| IP address | 85.11.187[.]8 | Hashtopolis use |
| Ports | 4332, 4432 | Beaconing, usually over HTTPS |
| Login IPs | 104.28.155[.]27 (Jun 19–20); 185.136.15[.]43 and 185.136.15[.]66 (Jun 27–Jul 23); 185.199.199[.]56 (Jun 25); 193.8.186[.]33 (Jun 18–Jul 20); 45.227.254[.]210 (Jun 18–Jul 23) | Brute force or successful login with compromised accounts |
| Login IPs | 77.91.118[.]10 (Jun 18–Jul 5); 80.75.212[.]113 (Jun 26–Jul 5); 87.251.64[.]13 (Jun 18–Jul 22); 87.251.64[.]16 and 87.251.64[.]17 (Jun 18–Jul 20); 87.251.64[.]44 (Jul 4); 66.175.220[.]111 (Jul 17–19) | Brute force or successful login with compromised accounts |
| Account names | adminin, admin, forticloud-tech, gttadmin, Technical_support, my_admin, fortiAdmin, fgtsecure, districtadmin, roadmin |
Compromised or suspicious accounts seen on victim devices |
| Account names | adminsslvpn, support_fortinet, forti_support2, forticloud-sync, pakedge, system_config, itadmin, IT_Manager, fgtsec |
Compromised or suspicious accounts seen on victim devices |
| Tools | Hashcat, Hashtopolis | Offline password cracking |
How to read these: several account names, such as admin and itadmin, are common in legitimate setups. A match is a reason to check who created the account and when, not proof of compromise on its own. Names that imitate Fortinet support or cloud services, like forticloud-sync or support_fortinet, deserve the closest look.
Enterprise Impact: What’s Actually at Risk
Network access, not just the firewall: The advisory describes attackers moving from the FortiGate into Active Directory enumeration and internal password spraying. A compromised VPN gateway should be treated as a possible domain-level incident.
Availability: Lockouts can leave teams unable to change firewall rules during an incident, which is exactly when they need to.
Ransomware exposure: Access is being sold to ransomware affiliates. An organization on the compromised list that has not yet been hit may simply not have been sold yet.
Disclosure and insurance: If you find attacker accounts, document when they were created, what they could reach and what you changed. Regulators and insurers will ask, and the advisory notes recovery may take more than patching and a password reset.
What Security Leaders Should Do Next
Today
- Inventory every internet-facing FortiGate and SSL VPN gateway, including branch and DR units.
- Export logs and a config backup first so you keep the evidence, then list every local admin and VPN account and compare it with a known-good configuration.
- Search for the 19 account names in the advisory and for any admin account nobody can explain. Confirm each legitimate admin can still log in.
- End all active admin and VPN sessions and reset every Fortinet admin and VPN password, starting with internet-facing devices.
- Restrict management access to trusted hosts or a local-in policy, or remove internet-facing administration entirely.
Within 48 hours
- Enforce phishing-resistant MFA for all remote access and admin accounts.
- Move admin password storage to PBKDF2 and remove legacy hashes, following Fortinet guidance for FortiOS 7.2.11 and later.
- Audit REST API keys: delete unknown keys, rotate the rest.
- Hunt the IP list in firewall, VPN, authentication and domain controller logs as far back as June 18, after checking each IP against current telemetry.
- If anything matches, run an incident: isolate the device, scope lateral movement, report to the FBI or USSS, and plan eviction before tipping off the intruder.
Long-term
- Track identity on edge devices alongside firmware versions: local accounts, API keys and hash format belong in the same dashboard.
- Keep at least 12 months of edge-device logs so late advisories can still be checked.
- Alert on admin account creation, deletion and password changes on firewalls and VPNs, and treat an admin lockout as a security event.
Get zero-day alerts before they hit the headlines
DataWater’s executive threat briefing: the exploited CVEs, the deadlines and the first three actions to take.
Winners and Losers
| Better positioned | More exposed |
|---|---|
| Teams with no internet-facing FortiGate administration | Organizations whose admin GUI or SSL VPN portal faces the internet with password-only login |
| Teams already on PBKDF2 admin password storage | Devices still writing legacy SHA-256 hashes, where every reset creates a new crackable hash |
| SOCs that alert on admin account changes | Programs that only track firmware versions and KEV deadlines |
| Teams with long edge-device log retention | Teams whose June and July logs have already rolled off |
Final Executive Takeaway
FortiBleed is a credential problem wearing a firewall’s clothes.
The FBI and Secret Service are telling defenders that the attackers have not gone away, that they now lock owners out, and that the access is being sold to ransomware crews. None of that is fixed by a firmware update.
Audit the accounts. Reset with PBKDF2 in place. Turn on phishing-resistant MFA. Take management off the internet.
Frequently Asked Questions
What is FortiBleed?
FortiBleed is a credential-harvesting and access-brokering campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. FortiBleed operators use leaked passwords, password spraying and offline hash cracking to get in, then sell access. SOCRadar has verified 86,644 compromised devices across 194 countries.
Is FortiBleed still active in October 2026?
Yes. A joint FBI and U.S. Secret Service advisory dated October 6, 2026 (JCSA-20261006-01) says FortiBleed operations continue, with attackers still scanning exposed FortiGate devices and using previously obtained credentials. The advisory also reports administrators being locked out of their own devices.
Is there a CVE or patch for FortiBleed?
No. The FBI/USSS FortiBleed advisory references no CVE, and there is no CISA KEV entry or federal due date. FortiBleed relies on stolen and cracked credentials, so the remedy is ending sessions, resetting Fortinet admin and VPN passwords, enforcing phishing-resistant MFA and storing admin credentials with PBKDF2.
How do FortiBleed attackers lock out FortiGate administrators?
According to the FBI/USSS advisory, FortiBleed attackers create their own admin accounts on a compromised FortiGate, then change the passwords of the original accounts or delete them. That blocks the legitimate owners and helps the attackers keep persistence while they move laterally.
What are the FortiBleed indicators of compromise?
The October 6 FortiBleed advisory lists infrastructure IPs including 45.154.12[.]132 (C2) and 85.11.187[.]8 (Hashtopolis), beacon ports 4332 and 4432, thirteen login IPs observed between June 18 and July 23, 2026, and 19 suspicious FortiGate account names such as forticloud-sync, support_fortinet, fortiAdmin and adminsslvpn. Verify IPs against current telemetry before blocking.
Who is behind FortiBleed?
The FBI/USSS advisory does not name a FortiBleed actor. Media reports describe a Russian-speaking initial access broker, and the advisory says INC/Lynx and Payload ransomware affiliates have used the FortiBleed access chain as an entry point.
Is resetting FortiGate passwords enough to stop FortiBleed?
Not on its own. FortiBleed cracks legacy SHA-256 password hashes offline, so the FBI/USSS advisory pairs FortiGate password resets with PBKDF2 storage, phishing-resistant MFA, removal of internet-facing admin access, a review of all accounts and API keys, and log hunting for lateral movement.
Sources
Primary source: FBI and U.S. Secret Service joint advisory JCSA-20261006-01 (October 6, 2026), including IoC tables and mitigations. Additional reporting reviewed: The Hacker News, BleepingComputer, Help Net Security and SecurityWeek (attribution, history and tooling details, single-source where noted). Reflects public reporting as of October 8, 2026.
