FBI Warns FortiBleed Attacks Continue to Lock Out FortiGate VPN Admins

· Original article ↗

Summary

The FBI says attackers are using stolen credentials to compromise exposed FortiGate devices, crack captured password hashes, and lock out administrators; some attacks have served as an entry point for ransomware affiliates.

Key points

  • Attackers target exposed Fortinet firewalls and SSL VPN gateways using leaked or stolen credentials, credential stuffing, and password spraying.
  • After gaining access, they extract authentication data and use distributed GPU resources to crack password hashes offline.
  • Attackers may create administrator accounts, remove or reset legitimate admins, establish persistence, and attempt lateral movement.
  • The FBI says the attack chain has been used as an initial entry point for ransomware affiliates, including INC/Lynx and Payload.
  • An exposed backend server revealed automated scanning, credential-validation and target-prioritization tools, along with VPN configurations and target lists.
  • The FBI recommends restricting external access, ending active VPN sessions, enforcing MFA, and checking logs for unauthorized changes and suspicious activity.
  • The FBI says remediation may require more than patching and password resets; it also recommends PBKDF2 for administrator password storage instead of legacy SHA-256 hashes.

Article Details

Event Type
Ongoing credential-based intrusions into exposed FortiGate firewalls and SSL VPN gateways
Impact
The FBI reports that attackers have extracted authentication data, created administrator accounts, and in some incidents deleted existing administrator accounts or changed their passwords, locking legitimate administrators out. The attack chain has also been observed as an initial entry point for ransomware affiliates. SOCRadar estimates that 86,644 devices were compromised.

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

Tools

Related Articles