FortiBleed Attackers Locking Victims Out of Fortinet Devices

https://www.securityweek.com/wp-content/uploads/2026/10/Fortinet.jpeg

The FortiBleed credential-harvesting and access-broker campaign is still active, and attackers are locking organizations out of their Fortinet devices.

Targeting internet-accessible Fortinet FortiGate firewalls and SSL VPN appliances, the campaign started in June.

Fortinet’s analysis of the attacks revealed that the attackers were using previously compromised credentials and brute-force techniques to take over poorly protected devices.

Within a week, the attacks hit over 86,000 Fortinet devices in 190 countries, and a Russian initial access broker was blamed for the campaign.

Now, SOCRadar says it has confirmed the compromise of approximately 86,644 devices in 194 countries. The attackers are searching for accessible firewalls and using compromised credentials to take them over.

“[This] is a count of confirmed-compromised devices, not an exposure estimate. Devices breached months ago remain in the actors’ validated inventory,” SOCRadar notes.

Advertisement. Scroll to continue reading.

In a joint advisory(PDF) released this week, the FBI and the...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE