FortiBleed Campaign Continues to Target Fortinet Devices, Leading to Lockouts and Ransomware
The FortiBleed campaign remains an active threat, enabling attackers to compromise Fortinet firewalls and VPNs, leading to user lockout or serving as an entry point for ransomware attacks.

The ongoing FortiBleed campaign continues to pose a significant threat to organizations utilizing Fortinet firewalls and VPN gateways. This campaign focuses on credential compromise, allowing malicious actors to gain unauthorized access to sensitive systems. The primary impacts observed include the potential for attackers to disable legitimate user accounts or change passwords, effectively locking users out of their own systems. This lockout scenario can be particularly disruptive, requiring remediation efforts that extend beyond standard patching and password reset procedures.
Beyond account lockout, the FortiBleed attack chain has emerged as a concerning initial access vector for ransomware affiliates. This means that compromised Fortinet devices are being used as a stepping stone for more destructive attacks, where ransomware is deployed to encrypt critical data and extort victims. The FBI and Secret Service have issued a joint alert highlighting these persistent dangers, underscoring the severity and evolving nature of the threat.
When FortiBleed was first identified, initial reports indicated a widespread compromise, with SOCRadar verifying over 86,000 compromised devices across nearly 200 countries. Further analysis suggests the campaign's scope is even broader, with estimates pointing to hundreds of thousands of firewalls being targeted. This extensive reach highlights the pervasive risk associated with vulnerable Fortinet deployments.
The sophisticated nature of the FortiBleed campaign lies in its ability to leverage compromised credentials to not only gain access but also to establish persistence. Attackers can create new administrative accounts, further entrenching their presence within a victim's network. This makes the threat particularly insidious, as standard security measures may prove insufficient to detect or evict the intruders.
The FBI and Secret Service alert specifically mentions that initial access brokers are actively utilizing FortiBleed to facilitate ransomware operations. This collaboration between different cybercriminal elements amplifies the overall threat landscape, as specialized groups focus on gaining initial access and then handing over the compromised environment to ransomware gangs.
To mitigate the risks associated with FortiBleed, security agencies recommend several key actions for Fortinet customers. These include restricting external management access or removing internet administration entirely, resetting all credentials, implementing multi-factor authentication (MFA), and diligently reviewing firewall and VPN user accounts for any unauthorized modifications. Furthermore, organizations are advised to scrutinize their logs for signs of lateral movement within the network and to enable secure credential storage mechanisms.
The agencies are actively seeking information and indicators of compromise (IoCs) from affected organizations. Sharing details such as attacker IP addresses and any usernames observed being used by the threat actors can significantly aid in tracking and disrupting the campaign. The continued active exploitation of Fortinet devices underscores the critical need for organizations to remain vigilant and apply recommended security best practices.