Cyberscoop FortiBleed Campaign Targets Fortinet Firewalls and VPNs, Leads to Ransomware Risks
Article Content
- •FortiBleed exploits reused credentials to access Fortinet devices.
- •Over 400,000 firewalls have been targeted globally.
- •Remediation may require more than just patching and password resets.
The FortiBleed campaign, a credential compromise threat targeting Fortinet firewalls and SSL VPN gateways, remains active as of October 6, 2026. The FBI and U.S. Secret Service issued a warning about ongoing attacks that exploit reused or leaked credentials, allowing attackers to lock users out of their accounts and potentially lead to ransomware incidents. Initial access brokers are reportedly passing access to ransomware affiliates like INC/Lynx and Payload. Affected organizations may require remediation beyond standard patching and password resets due to account lockouts. SOCRadar's investigation revealed over 400,000 targeted firewalls globally, indicating a broader scope than previously understood. Recommendations include restricting external management, resetting credentials, and implementing multifactor authentication. The advisory does not cite specific CVEs, emphasizing the need for vigilance beyond patching.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track INC/Lynx and Fortinet in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected?
What should organizations do to protect themselves?
Is there a patch available for this issue?
Continue Reading
Ransomhouse Targets Pertamina in Latest Ransomware Attack Ransomhouse has claimed a new victim, Pertamina, following the exposure of FortiOS SSL-VPN credentials due to the 'FortiBleed' vulnerability (CVE-2022-40684). This vulnerability was publicly disclosed on October 18, 2022, and has been actively exploited since October 11, 2022. The attack has led to the publication of…
Multiple Ransomware Attacks Target Various Organizations In September 2026, multiple organizations, including watchops.com and geekybunch.com, were reported as victims of ransomware attacks by the group known as 'unsafe'. The incidents were listed on dark web leak sites, but details regarding the nature of the attacks, such as data encryption or theft, remain vague. The…