FBI Warns FortiBleed Attacks Continue to Lock Out FortiGate VPN Admins

Summary
The FBI says attackers are using stolen credentials to compromise exposed FortiGate devices, crack captured password hashes, and lock out administrators; some attacks have served as an entry point for ransomware affiliates.
Key points
- Attackers target exposed Fortinet firewalls and SSL VPN gateways using leaked or stolen credentials, credential stuffing, and password spraying.
- After gaining access, they extract authentication data and use distributed GPU resources to crack password hashes offline.
- Attackers may create administrator accounts, remove or reset legitimate admins, establish persistence, and attempt lateral movement.
- The FBI says the attack chain has been used as an initial entry point for ransomware affiliates, including INC/Lynx and Payload.
- An exposed backend server revealed automated scanning, credential-validation and target-prioritization tools, along with VPN configurations and target lists.
- The FBI recommends restricting external access, ending active VPN sessions, enforcing MFA, and checking logs for unauthorized changes and suspicious activity.
- The FBI says remediation may require more than patching and password resets; it also recommends PBKDF2 for administrator password storage instead of legacy SHA-256 hashes.
Article Details
- Event Type
- Ongoing credential-based intrusions into exposed FortiGate firewalls and SSL VPN gateways
- Impact
- The FBI reports that attackers have extracted authentication data, created administrator accounts, and in some incidents deleted existing administrator accounts or changed their passwords, locking legitimate administrators out. The attack chain has also been observed as an initial entry point for ransomware affiliates. SOCRadar estimates that 86,644 devices were compromised.
MITRE ATT&CK
T1078 · Valid AccountsAttackers use previously leaked or otherwise obtained credentials to access exposed devices.T1110.002 · Password CrackingAttackers use Hashcat and Hashtopolis to crack stolen password hashes offline.T1110.003 · Password SprayingThe FBI identifies password spraying as a way attackers obtain logins.T1110.004 · Credential StuffingThe FBI identifies credential stuffing as a way attackers obtain logins.T1136 · Create AccountThe FBI says the threat actor creates administrator accounts in some incidents.T1531 · Account Access RemovalThe FBI says attackers delete existing administrator accounts or change their passwords, denying victims access.
Threat Actors
Malware
INC/Lynx ransomwareAccording to the FBI, " the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates." Some groups benefiting from this are INC/Lynx ransomware and Payload ransomware.Payload ransomwareAccording to the FBI, " the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates." Some groups benefiting from this are INC/Lynx ransomware and Payload ransomware.
Vendors
Products
Tools
hashcatThey then extract additional authentication data from compromised devices and use a distributed GPU cluster running Hashcat and Hashtopolis to crack offline the stolen password hashes.HashtopolisThey then extract additional authentication data from compromised devices and use a distributed GPU cluster running Hashcat and Hashtopolis to crack offline the stolen password hashes.