FBI Warns of Critical FortiBleed Attacks Exploiting Fortinet Firewalls and VPNs
Key Takeaways A widespread campaign, dubbed FortiBleed, is actively compromising Fortinet FortiGate firewalls and SSL VPN gateways globally. The attacks leverage reused, leaked, or weak credentials,...
Key Takeaways
- A widespread campaign, dubbed FortiBleed, is actively compromising Fortinet FortiGate firewalls and SSL VPN gateways globally.
- The attacks leverage reused, leaked, or weak credentials, along with legacy password hashing, rather than a new vulnerability.
- Over 86,000 devices across 194 countries have been affected, with threat actors gaining persistent access and potentially selling it to ransomware groups.
- The FBI and U.S. Secret Service have issued an urgent advisory, providing detailed mitigation steps and Indicators of Compromise (IOCs).
The Federal Bureau of Investigation (FBI) and the U.S. Secret Service (USSS) have jointly issued a critical cybersecurity advisory, warning organizations about the active FortiBleed campaign. This ongoing operation specifically targets internet-accessible Fortinet FortiGate firewalls and SSL VPN gateways, posing a significant risk to global network infrastructure.
Table Of Content
Reports indicate that this credential-compromise effort has impacted more than 86,644 devices spanning 194 nations. Organizations with Fortinet management or remote-access services exposed to the internet are particularly vulnerable to these attacks.
It is important to note that FortiBleed does not exploit a newly discovered Fortinet vulnerability. Instead, the attackers are reportedly exploiting weak, reused, or previously leaked credentials to gain unauthorized access to FortiGate appliances. A contributing factor to the campaign’s success is the abuse of legacy SHA-256 password storage, which enables stolen authentication data to be efficiently processed and cracked using distributed infrastructure.
Investigators discovered the scope of this operation after its operators inadvertently exposed a backend server. This server contained critical operational data, including attack tools, target information, and detailed workflows, providing significant insight into the adversary’s methods.
FortiBleed Campaign Exploits
The exposed infrastructure revealed a highly organized access-broker operation. The attackers systematically scanned for publicly reachable FortiGate SSL VPN portals, then tested stolen passwords, cracked password hashes, and verified compromised accounts. Once validated, this access was then sold to other cybercriminal entities.
The threat actors primarily employed credential stuffing and password spraying techniques. These methods involve attempting to log in using large lists of credentials obtained from prior data breaches and infostealer logs.
Upon successful entry, the attackers often establish persistence by creating new FortiGate administrator accounts. This allows them to maintain access even if original compromised credentials are reset. From there, they proceed to enumerate Active Directory users, identify privileged accounts, and attempt to move laterally within the victim’s network.
A significant concern highlighted in the advisory is the potential for organizations to lose control over their own Fortinet devices. The threat actors have been observed changing legitimate administrator passwords, disabling existing accounts, or entirely deleting them after creating their own persistent access points.
FortiBleed MITRE ATT&CK Techniques
| Tactic | Technique | MITRE ID |
|---|---|---|
| Reconnaissance | Active Scanning | T1595 |
| Initial Access | Exploit Public-Facing Application | T1190 |
| Credential Access | Password Spraying | T1110.003 |
| Credential Access | Credential Stuffing | T1110.004 |
| Credential Access | Credential Dumping | T1003 |
| Credential Access | Password Cracking | T1110.002 |
| Persistence | Create Local Account | T1136.001 |
| Defense Evasion / Initial Access | Valid Accounts | T1078 |
| Discovery | Account Discovery | T1087 |
| Exfiltration | Exfiltration Over C2 Channel | T1041 |
| Impact | Account Access Removal | T1531 |
This tactic of locking out legitimate administrators can severely delay incident response efforts, allowing attackers more time to operate within the compromised environment. The FBI and USSS also warned that FortiBleed activity has been directly linked to initial-access brokers who facilitate ransomware operations. Downstream connections to ransomware families such as INC/Lynx and Payload ransomware have been reported. This means a compromised Fortinet firewall or VPN gateway could serve as the initial entry point for a broader, enterprise-wide ransomware attack.
What You Should Do
- Immediate Account Review: Thoroughly audit all Fortinet administrative and VPN accounts, paying close attention to any unfamiliar or suspicious accounts (e.g.,
forticloud-sync,fgtsecure,forti_support2,Technical_support). - Investigate Anomalies: Look for unexpected REST API keys, unauthorized configuration changes, suspicious authentication attempts, and connections to known malicious infrastructure detailed in the advisory.
- Restrict External Access: Implement strict access controls for external management interfaces, utilizing trusted hosts or local-in policies. Where feasible, eliminate internet-based administration entirely.
- Reset Credentials and Sessions: Immediately terminate all active administrative and VPN sessions. Reset all Fortinet VPN and administrator credentials across your environment.
- Enforce MFA: Mandate phishing-resistant multifactor authentication (MFA) for all remote access and management interfaces.
- Update Hashing: For organizations running FortiOS, verify that administrator credentials are using PBKDF2 for password hashing, migrating away from weaker legacy methods.
- Log Analysis: Regularly review firewall, VPN, authentication, and domain controller logs to detect unauthorized accounts, suspicious successful logins, lateral movement, and attempts to alter device configurations.
- Apply IOCs: Use the provided Indicators of Compromise (IOCs) to proactively hunt for malicious activity within your network.
Indicators of Compromise (IOCs)
| IOC Type | Indicator | Key Detection Point |
|---|---|---|
| C2 | 45.154.12.132 |
Investigate firewall, VPN, proxy, and DNS connections. |
| Proxy | 154.202.59.169, 103.27.186.156 |
Check for connections to attacker relay infrastructure. |
| Beacon Relay | 45.155.250.158 |
Hunt HTTPS traffic on ports 4332 and 4432. |
| Password Cracking | 85.11.187.8 |
Associated with FortiBleed password-cracking activity. |
| Related Infrastructure | 193.8.187.2, 193.8.187.42 |
Linked to the FortiBleed attack chain. |
| Brute Force / Login Sources | 104.28.155.27, 185.136.15.43, 185.136.15.66, 193.8.186.33, 45.227.254.210, 77.91.118.10, 80.75.212.113 |
Hunt for brute-force attempts and compromised logins. |
| Brute Force / Login Sources | 87.251.64.13, .16, .17, .44, 66.175.220.111, 185.199.199.56 |
Check authentication activity and compromised accounts. |
| Suspicious Accounts | forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet |
Check for unauthorized persistence accounts. |
| Network Behavior | Ports 4332, 4432 |
Investigate unusual HTTPS traffic. |
| Device Changes | New admin accounts, password changes, unknown API keys | Review for persistence and unauthorized access. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.