Las Vegas/ Science, Tech & Medicine

FortiBleed Hackers Breach 86,000 Firewalls, Lock Out Admins in 194 Countries

AI Assisted Icon
Published on October 06, 2026
FortiBleed Hackers Breach 86,000 Firewalls, Lock Out Admins in 194 CountriesSource: Tony Hisgett / Wikimedia Commons

More than 86,644 Fortinet FortiGate firewalls across 194 countries have been compromised in a credential-harvesting campaign so aggressive that some victim organizations found themselves locked entirely out of their own systems. The operation, known as FortiBleed, doesn't rely on a software flaw at all — it exploits reused passwords, leaked logins, and outdated password storage to break in, then deletes or changes administrator accounts to seize control.

The warning came Tuesday in a joint cybersecurity advisory from the FBI and U.S. Secret Service, shared publicly by FBI Las Vegas

on X after FBI Cyber Division first posted the alert. The campaign has also involved unauthorized accounts.

Federal authorities are urging organizations to terminate active administrative and VPN sessions, reset credentials, enforce phishing-resistant multi-factor authentication, and restrict management access using trusted host lists.

The scale figures have changed as researchers counted different snapshots of the campaign. In its June 18 alert, CISA cited credential exposure involving approximately 74,000 Fortinet devices; SOCRadar’s later tally reached 86,644. SOCRadar notes that security firms may count different things—such as devices, IP addresses or firewall URLs—and update their totals as the investigation develops, so the figures are not necessarily measuring an identical set.

A Campaign Built on Bad Passwords, Not a Zero-Day

The FortiBleed name was first used by SOCRadar. In June, security researcher Volodymyr “Bob” Diachenko discovered an exposed dataset on an internet-accessible server, which threat intelligence firm Hudson Rock analyzed. Independent researcher Kevin Beaumont went on to verify active login credentials across multiple compromised organizations inside that dataset.

FortiBleed has been associated with weak password hygiene and reused credentials, and no confirmed CVE or zero-day has been identified.

The technical mechanism behind the credential theft involved a custom Golang-based packet sniffer called FortigateSniffer, which abused FortiOS's native diagnostic command to passively capture authentication traffic across two dozen protocols, Security Affairs reported. The sniffer let attackers harvest both cleartext and hashed passwords from network traffic flowing through compromised appliances.

Older Firmware Left Credentials Especially Exposed

FortiGate firewalls running FortiOS firmware older than versions 7.6.1, 7.4.8, or 7.2.11 were particularly vulnerable to hash-cracking because they stored administrative credentials using legacy SHA-256 hashing rather than the more secure PBKDF2 method, according to Trend Micro. The old hash remains in place until an administrator logs in again.

A firmware upgrade alone may not finish the password-storage fix. Fortinet’s documentation says passwords stored under the older SHA-256 scheme remain that way until each administrator successfully logs in after the upgrade, when the password is converted to PBKDF2. That leaves organizations needing to verify not only the installed FortiOS version but also that administrator accounts have completed the post-upgrade login.

Analysts at SOCRadar reported attempts against 320,777 FortiGate targets globally. IT services was among the sectors hit heavily.

Stolen Logins Tied to Ransomware

The fallout extended well beyond credential theft. FortiBleed has also been linked to the Lynx and INC ransomware groups.

Fortinet’s perimeter devices have also been targeted in campaigns that did exploit software vulnerabilities. In a 2021 advisory, the FBI and CISA said they had observed attackers exploiting FortiOS SSL-VPN flaw CVE-2018-13379 to gain access before follow-on operations that included ransomware. The distinction matters here: that earlier activity involved a known software flaw, while the current FortiBleed campaign, as described by authorities, centers on exposed or reused credentials rather than a newly identified FortiOS vulnerability.

The FortiBleed dataset has been associated with several major global corporations.

What Organizations Can Do Now

Organizations should restrict management access to firewall portals.