Skip to content
FortiBleed Campaign Targets Fortinet Firewalls and VPNs, Leads to Ransomware Risks

FortiBleed Campaign Targets Fortinet Firewalls and VPNs, Leads to Ransomware Risks

First seen 7 Oct 2026, 06:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 07:28 UTC
  • •FortiBleed exploits reused credentials to access Fortinet devices.
  • •Over 400,000 firewalls have been targeted globally.
  • •Remediation may require more than just patching and password resets.

The FortiBleed campaign, a credential compromise threat targeting Fortinet firewalls and SSL VPN gateways, remains active as of October 6, 2026. The FBI and U.S. Secret Service issued a warning about ongoing attacks that exploit reused or leaked credentials, allowing attackers to lock users out of their accounts and potentially lead to ransomware incidents. Initial access brokers are reportedly passing access to ransomware affiliates like INC/Lynx and Payload. Affected organizations may require remediation beyond standard patching and password resets due to account lockouts. SOCRadar's investigation revealed over 400,000 targeted firewalls globally, indicating a broader scope than previously understood. Recommendations include restricting external management, resetting credentials, and implementing multifactor authentication. The advisory does not cite specific CVEs, emphasizing the need for vigilance beyond patching.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
FBI and Secret Service issue advisory
The advisory warns that the FortiBleed campaign is still active and poses risks of account lockouts and ransomware attacks.
Cyberscoop
Recent
SOCRadar identifies targeted firewalls
SOCRadar's investigation found over 400,000 Fortinet firewalls targeted by the FortiBleed campaign, indicating a significant threat.
Cyberscoop

More articles in this cluster (2)

Following this threat?

Track INC/Lynx and Fortinet in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
Fortinet FortiGate firewalls and SSL VPN gateways are the primary targets of the FortiBleed campaign.
What should organizations do to protect themselves?
Organizations should restrict external management, reset admin credentials, and enforce multifactor authentication.
Is there a patch available for this issue?
The advisory emphasizes that remediation requires more than just patching and password resets, as attackers may lock users out.