|

FortiBleed FBI Advisory: Admin Lockouts and New IoCs

Four months after FortiBleed first surfaced, the FBI and the U.S. Secret Service say the campaign has not stopped. Attackers are still logging in to exposed FortiGate firewalls with stolen passwords, and in some cases they are now deleting or resetting the real administrator accounts so the owners cannot get back in. There is no patch for this, because there is no bug. The fix is credential hygiene, and a lookback window long enough to reach June.

DataWater Threat Intelligence Desk | Published October 8, 2026 | 8-minute read

Threat level: High (active campaign)

New McAfee Banner
Keeper Confetti Image

What: FortiBleed, a credential-harvesting and access-brokering campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Joint FBI and USSS advisory JCSA-20261006-01, dated October 6, 2026.

Status: Ongoing. The advisory reports admin lockouts and says the chain has served as an entry point for ransomware affiliates. No CVE is referenced.

Deadline: None. With no CVE, there is no CISA KEV entry or federal due date. Treat exposed FortiGate management and VPN portals as an open incident until you have checked them.

Fix: No firmware patch closes this. End all admin and VPN sessions, reset every Fortinet admin and VPN password, enforce phishing-resistant MFA, store admin credentials with PBKDF2, and hunt for the advisory’s account names and IPs.

Key takeaways

  • FortiBleed is still active as of October 2026. The FBI and Secret Service say attackers keep scanning exposed FortiGate firewalls and logging in with credentials obtained earlier.
  • The new behavior is lockout. Intruders add their own admin accounts, then delete or reset the legitimate ones, which blocks the owner and protects the attacker’s foothold.
  • The advisory publishes concrete IoCs: 20 IP addresses, beacon ports 4332 and 4432, and 19 account names such as forticloud-sync and support_fortinet.
  • Password resets alone are not enough. The campaign cracks legacy SHA-256 hashes offline, so the advisory pairs resets with PBKDF2 storage and phishing-resistant MFA.
  • Most of the published login IPs were seen between June 18 and July 23, 2026. If your log retention is 90 days, part of that window is already gone.

Executive Summary

FortiBleed was never a one-week story. Federal investigators now say it is still producing victims.

DataWater first covered the FortiBleed credential exposure in June, and followed up when CISA issued guidance and the count reached 86,644 devices. On October 6, the FBI and the U.S. Secret Service released a joint advisory, JCSA-20261006-01, titled around continued FortiBleed operations and reports of lockouts. It publishes a concrete set of indicators: attacker infrastructure, IPs seen logging in with compromised accounts, and the account names attackers left behind.

The advisory describes an industrialized workflow. Scripts find reachable FortiGate SSL VPN portals. Leaked passwords and infostealer logs are sprayed against them. Password hashes taken from compromised devices are cracked on a rented GPU cluster with Hashcat and Hashtopolis. Valid access is filtered to weed out honeypots, ranked by the victim’s revenue and network layout, then packaged with working VPN configurations and sold. The FBI says ransomware affiliates, including INC/Lynx and Payload, have used this chain as a way in.

The bottom line: if you run an internet-facing FortiGate, check it today for the account names in this advisory, confirm your own admins can still log in, and make sure the credentials you reset are not stored in a format the attacker can crack again.

Why This Matters to CISOs and Security Leaders

This is a vulnerability program blind spot. Most edge-device programs are driven by CVEs and KEV deadlines. FortiBleed has neither. A FortiGate can be fully patched and still be owned by someone holding a valid admin password. If your dashboards only track firmware versions, they will show green on a compromised firewall.

Lockout changes the response playbook. When attackers delete or reset the real admin accounts, the first sign may be a network engineer who suddenly cannot log in. Teams need a pre-agreed path for that: out-of-band console access, a vendor support route, and a rule that a failed admin login on an edge device is escalated to security, not just to the help desk.

Edge devices remain the front door. FortiBleed sits alongside the exploited FortiMail zero-day CVE-2026-104286 and the NetScaler SAML zero-day CVE-2026-88779 on many teams’ edge-device lists this month. The difference is that this one is about identity, not code.

Executive insight

Ask your network team two questions this week: “Which local admin accounts exist on each FortiGate right now, and who created each one?” and “Are our FortiGate admin passwords stored with PBKDF2?” If either answer takes more than a day to produce, that gap is your FortiBleed exposure.

The Timeline

Date (2026) What happened
June The operators inadvertently expose a server holding harvested Fortinet credentials. One report says the June leak tied usernames and plaintext passwords to 73,932 firewall URLs in 194 countries (single-source figure).
June 18 Earliest date on the advisory’s list of IPs seen brute-forcing or logging in with compromised accounts
June 19 Tally of affected Fortinet devices reaches 86,644 across 194 countries, the figure SOCRadar has since verified
June CISA issues guidance to Fortinet customers: end sessions, reset passwords, use phishing-resistant MFA and PBKDF2
July SOCRadar links FortiBleed to INC and Lynx ransomware after gaining access to negotiation panels on a campaign server, according to one report
July 23 Latest date on the advisory’s list of malicious login IPs
Later (date unknown) The operators expose a backend directory of scanning, cracking, honeypot-filtering and target-ranking tooling, plus VPN configurations and target lists
Tuesday, Oct 6 FBI and USSS publish joint advisory JCSA-20261006-01 warning of continued operations and admin lockouts
Oct 7–8 The Hacker News, BleepingComputer, Help Net Security and SecurityWeek report the advisory

A firewall on the latest firmware can still belong to someone else. FortiBleed never needed a bug, only a password.

Vulnerability & Exploit Analysis

No CVE, and that is the point

The FBI/USSS advisory does not reference any CVE. FortiBleed works through credential stuffing, password spraying with previously leaked data, and offline cracking of password hashes pulled from devices that were already breached. The advisory’s MITRE ATT&CK mapping does list “Exploit Public-Facing Application,” but in the context of targeting exposed FortiGate infrastructure, not a named software flaw. Fortinet’s own analysis, as reported by SecurityWeek, also points to previously compromised credentials and brute force against poorly protected devices.

The weak link: legacy SHA-256 password storage

The advisory says the campaign takes advantage of legacy SHA-256 storage of admin passwords, which is far easier to crack offline than PBKDF2. Its guidance is to store administrator credentials with PBKDF2 and remove legacy hashes, following Fortinet’s guidance for FortiOS 7.2.11 and later. A reset on a device that still writes SHA-256 hashes gives an attacker who returns a fresh hash to crack.

Device condition FortiBleed risk What to do
Admin GUI or SSL VPN portal reachable from the internet High Restrict management to trusted hosts or a local-in policy; best is no internet-facing admin at all
Admin passwords stored as legacy SHA-256 High Move to PBKDF2 per Fortinet guidance (FortiOS 7.2.11 and later), then reset
Password-only VPN or admin login High Enforce phishing-resistant MFA on all remote access and admin accounts
Unknown or unreviewed REST API keys Elevated Remove unknown keys and rotate legitimate ones
SSH open to the internet Elevated Close it; the advisory says SSH may have been abused where the port was open

What happens after login

According to the advisory, attackers create new admin accounts for persistence, pull FortiOS user databases, session tokens and hashes, then use working credentials to enumerate Active Directory and spray passwords internally. One report adds that a Go-based tool called FortigateSniffer was used to capture authentication traffic across 24 protocols, and that stolen session cookies were reused for persistent access (single-source).

What nobody is talking about
The advisory came out on October 6, but nearly all of its login IPs were seen between June 18 and July 23. June 18 is now more than 110 days ago. Many firewall and SIEM deployments keep 90 days of logs, so the evidence that would show whether those IPs touched your devices may already have aged out. If that is your situation, the account-name list and a full config review are your best remaining evidence, and you should extend retention for edge devices before the next campaign.

Threat Intelligence Breakdown

Attribution: The FBI/USSS advisory does not name a specific actor. The Hacker News describes the operation as Russian-speaking and suspects an initial access broker; SecurityWeek reports that a Russian initial access broker has been blamed. The advisory itself names INC/Lynx and Payload ransomware affiliates as users of the access chain. Victim totals beyond the 86,644 device figure are unknown.

How the count is framed: SOCRadar describes 86,644 as confirmed-compromised devices in 194 countries, not an exposure estimate, and notes that devices breached months ago remain in the attackers’ validated inventory. One outlet describes the same figure as working device credentials.

Indicators of compromise (FBI/USSS advisory JCSA-20261006-01, defanged). The advisory warns that cloud-hosted IPs may since have been reassigned to benign services, so check them against current telemetry before blocking.

Type Indicator Context
IP address 45.154.12[.]132 Command-and-control server
IP address 154.202.59[.]169 Proxy node
IP address 103.27.186[.]156 Proxy node
IP address 45.155.250[.]158 Beacon relay
IP address 193.8.187[.]2, 193.8.187[.]42 Attack chain infrastructure
IP address 85.11.187[.]8 Hashtopolis use
Ports 4332, 4432 Beaconing, usually over HTTPS
Login IPs 104.28.155[.]27 (Jun 19–20); 185.136.15[.]43 and 185.136.15[.]66 (Jun 27–Jul 23); 185.199.199[.]56 (Jun 25); 193.8.186[.]33 (Jun 18–Jul 20); 45.227.254[.]210 (Jun 18–Jul 23) Brute force or successful login with compromised accounts
Login IPs 77.91.118[.]10 (Jun 18–Jul 5); 80.75.212[.]113 (Jun 26–Jul 5); 87.251.64[.]13 (Jun 18–Jul 22); 87.251.64[.]16 and 87.251.64[.]17 (Jun 18–Jul 20); 87.251.64[.]44 (Jul 4); 66.175.220[.]111 (Jul 17–19) Brute force or successful login with compromised accounts
Account names adminin, admin, forticloud-tech, gttadmin, Technical_support, my_admin, fortiAdmin, fgtsecure, districtadmin, roadmin Compromised or suspicious accounts seen on victim devices
Account names adminsslvpn, support_fortinet, forti_support2, forticloud-sync, pakedge, system_config, itadmin, IT_Manager, fgtsec Compromised or suspicious accounts seen on victim devices
Tools Hashcat, Hashtopolis Offline password cracking

How to read these: several account names, such as admin and itadmin, are common in legitimate setups. A match is a reason to check who created the account and when, not proof of compromise on its own. Names that imitate Fortinet support or cloud services, like forticloud-sync or support_fortinet, deserve the closest look.

Enterprise Impact: What’s Actually at Risk

Network access, not just the firewall: The advisory describes attackers moving from the FortiGate into Active Directory enumeration and internal password spraying. A compromised VPN gateway should be treated as a possible domain-level incident.

Availability: Lockouts can leave teams unable to change firewall rules during an incident, which is exactly when they need to.

Ransomware exposure: Access is being sold to ransomware affiliates. An organization on the compromised list that has not yet been hit may simply not have been sold yet.

Disclosure and insurance: If you find attacker accounts, document when they were created, what they could reach and what you changed. Regulators and insurers will ask, and the advisory notes recovery may take more than patching and a password reset.

What Security Leaders Should Do Next

Today

  1. Inventory every internet-facing FortiGate and SSL VPN gateway, including branch and DR units.
  2. Export logs and a config backup first so you keep the evidence, then list every local admin and VPN account and compare it with a known-good configuration.
  3. Search for the 19 account names in the advisory and for any admin account nobody can explain. Confirm each legitimate admin can still log in.
  4. End all active admin and VPN sessions and reset every Fortinet admin and VPN password, starting with internet-facing devices.
  5. Restrict management access to trusted hosts or a local-in policy, or remove internet-facing administration entirely.

Within 48 hours

  1. Enforce phishing-resistant MFA for all remote access and admin accounts.
  2. Move admin password storage to PBKDF2 and remove legacy hashes, following Fortinet guidance for FortiOS 7.2.11 and later.
  3. Audit REST API keys: delete unknown keys, rotate the rest.
  4. Hunt the IP list in firewall, VPN, authentication and domain controller logs as far back as June 18, after checking each IP against current telemetry.
  5. If anything matches, run an incident: isolate the device, scope lateral movement, report to the FBI or USSS, and plan eviction before tipping off the intruder.

Long-term

  1. Track identity on edge devices alongside firmware versions: local accounts, API keys and hash format belong in the same dashboard.
  2. Keep at least 12 months of edge-device logs so late advisories can still be checked.
  3. Alert on admin account creation, deletion and password changes on firewalls and VPNs, and treat an admin lockout as a security event.

Get zero-day alerts before they hit the headlines

DataWater’s executive threat briefing: the exploited CVEs, the deadlines and the first three actions to take.

Read more briefings

Winners and Losers

Better positioned More exposed
Teams with no internet-facing FortiGate administration Organizations whose admin GUI or SSL VPN portal faces the internet with password-only login
Teams already on PBKDF2 admin password storage Devices still writing legacy SHA-256 hashes, where every reset creates a new crackable hash
SOCs that alert on admin account changes Programs that only track firmware versions and KEV deadlines
Teams with long edge-device log retention Teams whose June and July logs have already rolled off

Final Executive Takeaway

FortiBleed is a credential problem wearing a firewall’s clothes.

The FBI and Secret Service are telling defenders that the attackers have not gone away, that they now lock owners out, and that the access is being sold to ransomware crews. None of that is fixed by a firmware update.

Audit the accounts. Reset with PBKDF2 in place. Turn on phishing-resistant MFA. Take management off the internet.

Frequently Asked Questions

What is FortiBleed?

FortiBleed is a credential-harvesting and access-brokering campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. FortiBleed operators use leaked passwords, password spraying and offline hash cracking to get in, then sell access. SOCRadar has verified 86,644 compromised devices across 194 countries.

Is FortiBleed still active in October 2026?

Yes. A joint FBI and U.S. Secret Service advisory dated October 6, 2026 (JCSA-20261006-01) says FortiBleed operations continue, with attackers still scanning exposed FortiGate devices and using previously obtained credentials. The advisory also reports administrators being locked out of their own devices.

Is there a CVE or patch for FortiBleed?

No. The FBI/USSS FortiBleed advisory references no CVE, and there is no CISA KEV entry or federal due date. FortiBleed relies on stolen and cracked credentials, so the remedy is ending sessions, resetting Fortinet admin and VPN passwords, enforcing phishing-resistant MFA and storing admin credentials with PBKDF2.

How do FortiBleed attackers lock out FortiGate administrators?

According to the FBI/USSS advisory, FortiBleed attackers create their own admin accounts on a compromised FortiGate, then change the passwords of the original accounts or delete them. That blocks the legitimate owners and helps the attackers keep persistence while they move laterally.

What are the FortiBleed indicators of compromise?

The October 6 FortiBleed advisory lists infrastructure IPs including 45.154.12[.]132 (C2) and 85.11.187[.]8 (Hashtopolis), beacon ports 4332 and 4432, thirteen login IPs observed between June 18 and July 23, 2026, and 19 suspicious FortiGate account names such as forticloud-sync, support_fortinet, fortiAdmin and adminsslvpn. Verify IPs against current telemetry before blocking.

Who is behind FortiBleed?

The FBI/USSS advisory does not name a FortiBleed actor. Media reports describe a Russian-speaking initial access broker, and the advisory says INC/Lynx and Payload ransomware affiliates have used the FortiBleed access chain as an entry point.

Is resetting FortiGate passwords enough to stop FortiBleed?

Not on its own. FortiBleed cracks legacy SHA-256 password hashes offline, so the FBI/USSS advisory pairs FortiGate password resets with PBKDF2 storage, phishing-resistant MFA, removal of internet-facing admin access, a review of all accounts and API keys, and log hunting for lateral movement.

Sources

Primary source: FBI and U.S. Secret Service joint advisory JCSA-20261006-01 (October 6, 2026), including IoC tables and mitigations. Additional reporting reviewed: The Hacker News, BleepingComputer, Help Net Security and SecurityWeek (attribution, history and tooling details, single-source where noted). Reflects public reporting as of October 8, 2026.

Similar Posts