The FBI Says 86,000+ Fortinet Firewalls Were Opened With Stolen Passwords — Treat Your Network Edge Like a Login Page

The FBI Says 86,000+ Fortinet Firewalls Were Opened With Stolen Passwords — Treat Your Network Edge Like a Login Page

2026-10-08

On October 6, 2026, the FBI and the U.S. Secret Service published a joint advisory warning that FortiBleed, a credential-theft campaign aimed at Fortinet FortiGate firewalls and VPN gateways, is still active. Citing security firm SOCRadar, the agencies say more than 86,644 devices across 194 countries have been compromised (FBI and USSS advisory JCSA-20261006-01, October 6, 2026).

Quick definitions: a FortiGate is Fortinet’s firewall, the box that sits between your network and the internet. Many also run an SSL VPN, the login portal remote staff use to get inside.

The takeaway for operators: this isn’t an exotic zero-day. It’s passwords. Attackers walked in with reused or leaked credentials and, in some cases, changed the locks behind them. If your firewall or VPN has an internet-facing login without strong multi-factor authentication (MFA), it’s an identity system, and it needs to be managed like one.

What the attackers did

The operation came to light because the attackers accidentally left their own backend server exposed. According to the advisory, they:

  • Scanned the internet for exposed FortiGate SSL VPN portals.
  • Tried leaked logins from old Fortinet leak dumps and infostealer logs (passwords scraped by malware from infected computers). That meant credential stuffing (replaying leaked username and password pairs) and password spraying (trying a few common passwords across many accounts).
  • Cracked more passwords by dumping password hashes from compromised devices and running them through a rented GPU cluster.
  • Created new admin accounts to stay in, then moved deeper into networks by mapping Active Directory.
  • Sold the access. Middlemen known as initial access brokers passed it to ransomware affiliates, including INC/Lynx and Payload.

Then there’s the lockout. Attackers sometimes deleted or changed passwords on legitimate admin accounts, so victims “may find themselves locked out of their systems,” with fixes “beyond standard patching and password resets” (FBI and USSS).

“Not a new vulnerability” is the scary part

Fortinet said on June 19, 2026, that FortiBleed “is not a new Fortinet vulnerability.” It pointed to credentials reused from earlier incidents and brute-force attacks on devices with weak passwords and no MFA. Fortinet also noted the same actor reportedly breached other vendors’ devices the same way (Fortinet PSIRT blog, June 19, 2026).

So this week’s advisory isn’t news because the bug is new. It’s news because the campaign hasn’t stopped, months after it surfaced in June (Infosecurity Magazine, October 8, 2026). The real scale may be bigger, too. Ensar Seker, chief information security officer at SOCRadar, told CyberScoop that his team later identified “more than 400,000 or 450,000 firewalls targeted by the wider operation” (CyberScoop, October 6, 2026).

John Strand, owner of the security firm Black Hills Information Security, put it bluntly: “I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access” (Infosecurity Magazine).

The edge-device checklist

Running Fortinet? Do this now. Running another brand? Do it anyway. The same playbook fits any internet-facing firewall or VPN. Steps 1 to 7 below come from the FBI and Secret Service advisory, with Fortinet’s guidance noted where it adds detail.

  1. Get admin off the internet. The advisory ranks the options: trusted hosts (good), a local-in policy (better), or no internet administration at all (best). In plain words, either only specific addresses can reach the admin page, or nobody on the internet can.
  2. Kill sessions, then reset everything. End all active admin and VPN sessions, then reset every VPN and admin password, starting with internet-facing systems.
  3. Turn on phishing-resistant MFA. This means methods like hardware security keys or passkeys, which can’t be tricked into handing a code to a fake login page. Require it on every remote-access and admin account.
  4. Audit the accounts you didn’t create. Compare your configuration with a known-good copy. Account names the FBI saw attackers create include fortiAdmin, forticloud-sync, itadmin, and support_fortinet. They’re designed to look boring.
  5. Check API keys. REST API keys let software manage the firewall automatically. Unknown ones are a back door. Remove them and refresh the legitimate ones.
  6. Upgrade how passwords are stored. The advisory blames legacy SHA-256 password storage for making cracking easier. Move admin credentials to PBKDF2, a deliberately slow hashing method that makes cracking far more expensive. Fortinet recommends upgrading to FortiOS 7.4, 7.6, or 8.0, which support it.
  7. Read the logs, including the domain controller. Look for unexpected admin logins, new VPN users, and signs of attackers moving between systems in your firewall, VPN, authentication, and domain controller logs. In the U.S., the agencies ask victims to report compromises to the FBI’s Internet Crime Complaint Center (IC3) or a local FBI or Secret Service field office.

The question nobody wants to ask

In plenty of growing companies, the firewall was set up years ago by a managed service provider or a long-gone IT lead, and nobody has logged in since. So ask three questions: Who has admin access? Is MFA on? When were the passwords last changed? If the answer is a shrug, you’ve found your project for the week. If nobody clearly owns the answer, our CIO vs. CTO vs. CISO breakdown can help you decide who should.

Soft next step

FortiBleed is a reminder that the riskiest door into your company may be a login page you forgot you had. Patching matters, but it doesn’t fix stolen passwords. Lock down admin access, enforce strong MFA, and audit your accounts now, not after the lockout.

Yellow Coop helps owners and operators review firewall, VPN, and identity setups — with fractional CTO ownership of security priorities alongside your IT provider. See the security and infrastructure work in our track record, or start at contact.

Internal links: Secure, What We Do, How We Engage, CIO vs CTO vs CISO, Track Record, Insights.

Sources