The US Federal Bureau of Investigation (FBI) and Secret Service (USSS) have warned that the FortiBleed cyber campaign remains an active threat to internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.
The campaign uses stolen or reused passwords to break into exposed Fortinet devices. Attackers can then steal authentication data, crack passwords and create new administrator accounts to keep access to compromised systems.
FortiBleed was first reported in June 2026 and has targeted thousands of devices worldwide. Authorities estimate that the operation obtained more than 86,000 working device credentials across 194 countries.
After gaining access, attackers can move deeper into company networks, search for valuable accounts and data, and steal information from network shares. Security agencies also believe the stolen access may be sold to other cybercriminals and used in ransomware attacks.
The FBI and USSS warned that attackers may delete or change existing accounts, potentially locking organizations out of their Fortinet devices.
Organizations that use FortiGate devices are advised to reset VPN and administrator passwords, enable phishing-resistant authentication, end active sessions, update security settings and review logs for suspicious activity. Companies that suspect a compromise should isolate affected devices, preserve logs and report the incident to authorities