Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

FBI Sounds Alarm as FortiBleed Campaign Persists, Locking Firms Out of Their Own Firewalls

Дата публикации: 07-10-2026 20:12:13

The FBI and Secret Service warn that FortiBleed continues compromising over 86,000 Fortinet firewalls worldwide. Attackers lock victims out of their own devices and feed access to ransomware groups. Organizations face complex recovery beyond simple password resets. Immediate hardening is required.

Основное содержимое страницы с новостью.

Tens of thousands of organizations remain exposed. Their Fortinet firewalls and VPN gateways sit on the public internet, quietly hemorrhaging credentials. On October 7, the FBI and U.S. Secret Service issued a fresh warning. The operation known as FortiBleed shows no signs of slowing.

More than 86,644 devices across 194 countries have already been compromised. That’s according to data verified by threat intelligence firm SOCRadar and cited directly in the joint advisory. Attackers aren’t done. They continue scanning for internet-facing FortiGate appliances, feeding stolen credentials back into the machine.

The consequences have grown sharper. Some victims discover they can no longer log in to their own security devices. Threat actors create new administrator accounts. Then they delete or alter the original ones. Persistence achieved. Access denied to the rightful owners.

“Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system,” the agencies stated in their advisory. The lockout forces companies into more complex recovery. Standard password resets won’t cut it.

This isn’t a zero-day flaw in FortiOS. No new vulnerability drives the breaches. Instead, attackers rely on credential reuse. They pull usernames and passwords from previous leaks and infostealer malware logs. Password spraying and stuffing campaigns follow. Success rates rise when organizations skip multi-factor authentication or expose management interfaces.

Once inside, the work accelerates. Compromised devices yield password hashes. These travel to offline cracking farms powered by GPU clusters running Hashcat and Hashtopolis. Cracked credentials get enriched. Scripts filter out honeypots. Targets sort by revenue and network value. High-priority victims move to the front of the queue.

A custom tool adds another layer. Called FortigateSniffer, the Go-based utility sniffs traffic across two dozen protocols. It captures authentication data in transit. Cleartext credentials and hashes flow back to the operators. The entire pipeline surfaced earlier this year after the attackers accidentally left a backend server exposed in an open directory. That mistake handed researchers an unprecedented look at the operation’s inner workings.

SOCRadar first detailed the campaign in June. Its researchers uncovered the exposed server and the massive credential trove. The operation targeted over 430,000 FortiGate systems worldwide. At least 19,000 received the sniffer tool before notifications began reducing the active count. By mid-year, validated working credentials stood at 86,644. The FBI advisory confirms the activity continues months later.

And the downstream effects prove troubling. Initial access brokers sell the footholds. Ransomware groups line up to buy. The advisory links FortiBleed to affiliates of INC and Lynx ransomware, as well as Payload. At least a dozen confirmed ransomware incidents trace back to these stolen credentials, according to earlier SOCRadar analysis referenced in The Register.

“The FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates,” the FBI and Secret Service warned. The pattern repeats. Perimeter device. Valid account. Lateral movement into Active Directory. Password spraying inside the network. Encryption soon follows.

Fortinet addressed the campaign earlier. The company stressed that no new vulnerability exists. Its PSIRT team pointed to credential reuse from past incidents combined with weak password practices and absent MFA. Customers must treat exposed management ports as high risk.

Yet exposure remains widespread. Many FortiGate appliances still listen on ports 443 or 10443 from the internet. Administrative interfaces appear in Shodan searches daily. The attackers know this. Their scanning never stops.

The latest advisory offers concrete steps. Organizations should immediately restrict management access to trusted IP ranges. Terminate all active administrative and SSL VPN sessions. Reset both firewall and VPN passwords. Switch password storage to the stronger PBKDF2 algorithm instead of legacy SHA-256. Enable phishing-resistant multi-factor authentication everywhere possible.

Review user accounts for unfamiliar names. The advisory lists several observed in compromised systems: adminin, fortiAdmin, fgtsecure, forticloud-tech, support_fortinet. Hunt for them. Check logs for unexpected configuration downloads or sniffer commands. Look for lateral movement signals once inside the network.

Recovery gets complicated for locked-out victims. In some cases, organizations must factory reset the appliance. That wipes configurations and requires full redeployment. Others regain access only after engaging Fortinet support with proof of ownership. Downtime mounts. Business impact grows.

The campaign reveals broader weaknesses. Too many enterprises still treat firewalls as set-and-forget appliances. Credentials harvested years ago retain value if never rotated. VPN configurations sold on underground markets provide instant network entry. The initial access broker model scales these compromises efficiently.

But the exposure of the backend server offered rare visibility. Researchers saw job logs, cracked credential databases, target lists sorted by company revenue, and scripts that automated almost every stage. The operation rented GPU resources. It filtered data aggressively. It packaged VPN configs and account lists for resale. Professional. Industrial. Persistent.

Recent coverage from The Record highlighted additional details. The agencies noted that recovered tooling provides an end-to-end view of target identification, credential validation, and network expansion. More than 20 affiliates played defined roles in scanning portals across 150 countries. The maturity surprised even seasoned analysts.

Help Net Security reported the same day that remediation now demands actions beyond patching. Account audits, session termination, and network segmentation become mandatory. The advisory urges organizations to share indicators of compromise with law enforcement. Fresh sightings could map the campaign’s current infrastructure.

So what happens next? The credential pool likely continues growing. Old compromises feed new ones. Ransomware operators maintain steady demand for reliable initial access. Fortinet customers who haven’t hardened their perimeter face ongoing risk.

Smaller firms often lack the staff to monitor every log or rotate every credential. Larger ones sometimes assume their firewall vendor handles the heavy lifting. Both assumptions fail here. The attackers exploit human and process gaps more than code flaws.

Security teams should treat this as a wake-up call. Inventory every internet-facing FortiGate device today. Map administrative access paths. Enforce MFA without exception. Segment networks so firewall compromise doesn’t equal domain compromise. Test recovery procedures for locked devices before an incident forces the issue.

The FBI and Secret Service aren’t issuing this alert for show. They see the lockouts. They see the ransomware handoffs. They see the campaign marching forward. Organizations that act now reduce their odds of joining the statistics. Those that delay may find themselves on the wrong side of a locked firewall with ransomware already inside.

FortiBleed didn’t start with a vulnerability announcement. It won’t end with one either. It ends when exposed devices disappear from the internet, when credentials stop being reused, and when multi-factor authentication becomes the baseline instead of the exception. That work falls to defenders. The clock is running.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Не секретные материалы: ФБР не знает, как хакеры похитили данные агентов07.5329-09-2026
2ShinyHunters FBI Data Breach: Leaked Spreadsheet Names Staff in China, Russia and HUMINT Roles06.5824-09-2026
3FBI wird gehackt – Cyberkriminelle entwenden heikle Personaldaten und Informationen zu Geheimaufträgen09.8630-09-2026
4FBI removes Accenture contractor after missed security patch led to breach08.8606-10-2026
5Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor08.0129-09-2026
6Two Federal Breaches Expose Millions of Sensitive Records in Rapid Succession011.8902-10-2026
7Группировка ShinyHunters заявляет, что взломала ФБР и похитила данные всех сотрудников09.5723-09-2026
8This Week in Security: FBI Gets Hacked, Muse Vulnerable to ClickFix, Popular Rust Developers at Risk, and New Attacks Against RSA030.125-09-2026
9Stolen FBI data reveals employees’ roles in intelligence and surveillance07.7924-09-2026

Классификация: Общество. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 10.4. Источник: www.webpronews.com.