Events Join us at the AWS Summit in Dubai on 30th September
Read

Locked Out: FBI Confirms FortiBleed Attackers Are Hijacking Fortinet Firewalls

A FortiBleed attack is locking firms out of their own Fortinet firewalls, the FBI warns, with stolen logins now feeding active ransomware crews.

TL;DR: Thousands of companies just lost the keys to their own front door. Federal investigators now confirm that the FortiBleed attack is still running, and the people behind it are changing passwords, deleting admin accounts, and shutting defenders out of the very firewalls meant to protect them.

What Happened?

The FBI and the Secret Service put out a joint warning this week. They say stolen logins tied to FortiBleed are being used to break into internet-facing Fortinet firewalls and SSL VPN gateways.

The campaign is not new. It is getting worse. Researchers tracking it have counted more than 86,644 hacked devices across 194 countries. By their estimate, that is close to 50% of every Fortinet firewall sitting on the open internet.

Here is the twist. During a break-in, the attackers create fresh accounts that were never on the device. Then they change or wipe the original passwords. The real owners get locked out of their own hardware while the intruders dig deeper into the network.

The logins are not cracked fresh each time. Many come from old breaches and from malware that quietly scrapes passwords off infected machines. Attackers feed those lists into the login page, pull password hashes from any box they get into, and crack the rest offline on racks of graphics cards built for speed.

FortiBleed · By The Numbers

Huge reach, and almost invisible

86,644
Devices hit
194
Countries
~50%
Of exposed Fortinet firewalls
12+
Ransomware attacks linked
Why it slips past you
Valid credentials No malware to flag No single flaw to patch

Device and country counts come from researchers tracking the campaign and are a snapshot, not a final tally. The reach keeps growing as more leaked logins are tried.

What’s the Impact?

This stopped being a password problem a while ago. Investigators have now tied FortiBleed to ransomware. Access brokers sell the stolen entry, and ransomware crews walk straight through the open door.

Researchers say they have already confirmed at least a dozen ransomware attacks that started this way, and the count keeps climbing. For a mid-sized company, one hijacked firewall can mean a full network takeover, stolen data, and a ransom note before anyone notices the logins changed.

The hardest part is spotting it. The attackers sign in with real usernames and real passwords, so the activity looks like normal admin work. No malware flags it, and no single flaw can patch it.

FortiBleed · Detection

No classic IOCs. Hunt the behavior.

There is no public list of malicious IPs, file hashes, or malware for FortiBleed, because the attackers sign in with stolen but valid credentials instead of dropping a payload. Investigators have asked victims to report so hard indicators can be built. Until then, hunt these log events on your Fortinet devices and connected directory.

✓
New accounts you did not create. Admin or local accounts added outside your normal provisioning process.
✓
Original accounts altered or gone. Existing admin users renamed, disabled, or deleted with no change ticket behind it.
✓
Logins from the wrong places. Admin or SSL VPN sign ins from new countries, hosting ranges, or odd hours.
✓
Config changes nobody approved. Edits to firewall rules, VPN settings, or user permissions outside a maintenance window.
✓
Logging quietly switched off. Audit or event logging disabled or reduced on the appliance.
✓
You get locked out. A sudden loss of access to your own admin accounts is a late and loud warning sign.
MITRE T1078 · Valid Accounts T1098 · Account Manipulation T1133 · External Remote Services

Important: an empty result does not prove you are clean. Attackers with admin control can edit the very logs you are checking. Pair log review with a full credential reset and session kill.

How to Avoid This

The agencies laid out clear steps, and none require a new product. Move firewall and VPN management off the public internet, and close anything that doesn’t need to face the world.

  • Kill every active admin and VPN session, then reset all passwords from scratch.
  • Turn on phishing-resistant multifactor authentication on every account.
  • Hunt your logs for new accounts you didn’t create, and admin changes nobody approved.
  • Upgrade to current FortiOS builds so stored passwords use stronger hashing and resist offline cracking.

One reminder worth repeating. Do not pay the ransom. Report the incident instead, because victim reports help investigators map the attack and warn the next target.

You Cannot Patch a Password. You can prove it is not being used against you.

FortiBleed works because there is nothing to patch and nothing obvious to catch. The real fix is not another alert feed. It is steady proof that your exposed edge isn’t already somebody else’s way in.

  • A Red Teammate probes your internet-facing edge the way an attacker would, surfacing weak logins and open management before a broker finds them first.
  • A SOC Teammate watches for the quiet tells of FortiBleed, like a brand new admin account or a login from a place it has no business coming from.
  • Attack findings flow straight into hardening work, so real weaknesses get fixed instead of sitting in a backlog.
  • Every consequential move waits for your team’s approval and lands in a full audit trail, so the software does the legwork while people keep control.
  • It all runs above the stack you already own, so there is no rip-and-replace to get going.