FBI and Secret Service Issue Joint Advisory on FortiBleed Campaign Compromising 86644 Firewalls Across 194 Countries
The FBI and U.S. Secret Service issued a joint advisory on October 6 describing FortiBleed, an active campaign against internet-facing FortiGate firewalls and SSL VPN gateways, citing
Patching and password rotation will not fix FortiGate estates where attackers deleted accounts or changed passwords, because owners cannot reach those devices to remediate them. The exposed backend shows a mature initial access broker pipeline of scanning, credential stuffing, GPU hash cracking, validation, and resale, and INC/Lynx and Payload affiliates are already buying. Intrusions on unremediated firewalls can therefore become extortion events without a separate exploit. Legacy SHA-256 password storage on unpatched FortiOS builds is the main exposure, and PBKDF2 migration and phishing-resistant MFA address it. U.S. government attribution arrived sooner than an earlier cycle expected, adding indicators, affiliate links, and lockouts. Sourcing is thin: one secondary outlet relays the advisory, and the Singapore document covers only the earlier leak. The lockouts and sales may instead reflect opportunistic resale of a stale credential dump with limited persistent access.
2 sources
- 86,644 Firewalls in 194 Countries Breached With Stolen Passwords -
The Cyber Express - Advisory on Credential Compromise of FortiGate Devices ("FortiBleed") -
Cyber Security Agency of Singapore