IC Technology & Cyber — 2026-10-08

FBI and Secret Service Issue Joint Advisory on FortiBleed Campaign Compromising 86644 Firewalls Across 194 Countries

BLUFUnremediated FortiGate estates now face direct ransomware risk because the exposed broker pipeline already feeds validated VPN access to active extortion affiliates, bypassing any need for a novel exploit.

The FBI and U.S. Secret Service issued a joint advisory on October 6 describing FortiBleed, an active campaign against internet-facing FortiGate firewalls and SSL VPN gateways, citing SOCRadar data verifying more than 86,644 compromised devices in 194 countries, The Cyber Express reported 1. The advisory says attackers use reused or leaked credentials and legacy SHA-256 password storage, and some victims were locked out after attackers deleted accounts or changed passwords 1. The actors accidentally exposed their backend server, which showed an initial access broker operation that cracked harvested hashes on a GPU cluster and sold access to downstream actors, including INC/Lynx and Payload ransomware affiliates 1. Singapore's Cyber Security Agency had reported the campaign on June 22, citing a leaked database covering over 70,000 devices, and recommended session termination, credential resets, MFA, PBKDF2 hashing and possible factory resets 2.

Analysis
Patching and password rotation will not fix FortiGate estates where attackers deleted accounts or changed passwords, because owners cannot reach those devices to remediate them. The exposed backend shows a mature initial access broker pipeline of scanning, credential stuffing, GPU hash cracking, validation, and resale, and INC/Lynx and Payload affiliates are already buying. Intrusions on unremediated firewalls can therefore become extortion events without a separate exploit. Legacy SHA-256 password storage on unpatched FortiOS builds is the main exposure, and PBKDF2 migration and phishing-resistant MFA address it. U.S. government attribution arrived sooner than an earlier cycle expected, adding indicators, affiliate links, and lockouts. Sourcing is thin: one secondary outlet relays the advisory, and the Singapore document covers only the earlier leak. The lockouts and sales may instead reflect opportunistic resale of a stale credential dump with limited persistent access.
2 sources
  1. 86,644 Firewalls in 194 Countries Breached With Stolen Passwords - The Cyber Express
  2. Advisory on Credential Compromise of FortiGate Devices ("FortiBleed") - Cyber Security Agency of Singapore

View in full brief →

UNCLASSIFIED // OPEN SOURCE