The FBI and US Secret Service have issued a warning about a persistent cyberattack campaign targeting Fortinet firewalls and SSL VPN gateways. The agencies confirmed that criminals are using credentials from previous breaches to gain unauthorized access to devices, often locking organizations out of their own systems by altering or deleting account passwords. The advisory, published earlier this week, highlights the scale of the threat, with security firm SOCRadar verifying over 86,644 compromised devices across 194 countries.
The attackers exploit internet-facing FortiGate firewalls and VPN gateways using credential stuffing and password spraying techniques. Once inside, they create new accounts to maintain persistence, extract password hashes, and crack them offline using GPU-accelerated clusters. In some cases, existing accounts are deleted to prevent organizations from regaining control, while the attackers attempt lateral movement within the network. The advisory links the campaign to ransomware groups, specifically identifying affiliates of INC/Lynx and Payload as active participants. SOCRadar previously reported at least 12 confirmed ransomware attacks stemming from these compromises.
How the attacks unfold
The campaign leverages credentials obtained from earlier data breaches and infostealer logs, which are then used to infiltrate Fortinet devices. Attackers prioritize maintaining access by creating unauthorized accounts and, in some instances, deleting legitimate ones. The extraction of password hashes allows them to crack credentials offline, reducing the risk of detection during the process. The FBI and Secret Service noted that initial access brokers have supplied compromised network access to ransomware affiliates, amplifying the impact of the breaches.
Organizations are advised to restrict internet-facing management access, terminate active administrative and VPN sessions, and reset all passwords. The agencies also emphasized the importance of enabling phishing-resistant multi-factor authentication (MFA) to mitigate the risk of credential-based attacks. While victim reporting is encouraged to help identify indicators of compromise, the advisory clarifies that organizations are not obligated to respond.
Ransomware and broader implications
The advisory underscores the connection between the FortiBleed campaign and ransomware operations. SOCRadar’s findings indicate that compromised credentials have been actively used by ransomware affiliates, with at least 12 confirmed attacks linked to the campaign. The FBI and Secret Service warned against paying ransoms, noting that such payments do not guarantee the recovery of data or prevent future attacks. Instead, they urged organizations to focus on securing their systems and reporting incidents to aid in broader threat intelligence efforts.
For professionals: Organizations using Fortinet firewalls or SSL VPNs should immediately audit administrative accounts, enforce phishing-resistant MFA, and review access logs for unauthorized sessions. The advisory’s emphasis on credential hygiene and session termination highlights the need for proactive security measures to prevent lateral movement by attackers.
What to watch
The ongoing nature of the campaign suggests that attackers will continue to exploit weak or reused credentials. Security teams should monitor for unusual account activity, particularly the creation of new accounts or the deletion of existing ones. The advisory’s call for victim reporting also indicates that further details about the campaign’s scope and tactics may emerge as more organizations come forward.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 7 Oct 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No recent or in-pipeline article covers this FortiBleed/Fortinet-related threat update.
- Checking for duplicates — New story pre_write:; No previously published or in-pipeline article covers this specific Fortinet FortiMail zero-day under active attack story.
- Writing the article — Draft created article_id=659 slug=fbi-confirms-86-644-fortinet-devices-compromised-via-fortibleed
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The advisory publication date is stated as 'earlier this week' and 'Tuesday' in the draft, but the source specifies 'Tuesday' (6 October 2026) relative to its publication date (7 October 2026). The draft should clarify the exact date (6 October 2026) or use 'Tuesday' with the source's publication context.
- Quote integrity: The draft does not include any blockquotes, so this check is not applicable. However, the 'For professionals' callout paraphrases the advisory's recommendations rather than quoting verbatim, which is acceptable under style rules.
- No copied phrasing: The draft avoids direct copying but echoes some phrasing from the source (e.g., 'credential stuffing and password spraying techniques', 'GPU-accelerated clusters'). While restructured, these clusters are close to the source wording and could be further paraphrased.
- Style compliance: The draft adheres to structure and tone but could improve specificity in the headline. 'FortiBleed' is not explicitly named in the headline, though it is central to the story. The headline should include it (e.g., 'FBI confirms 86,644 Fortinet devices compromised via FortiBleed exploit').
- Audience relevance and notability: The story is highly relevant to hosting, cloud, and security professionals, with clear actionable takeaways. No issues here.
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Reused library image reused image #228
- Linking related stories — Linked 5 relations from 330 candidates
- Publishing — Published fbi-confirms-86-644-fortinet-devices-compromised-via-fortibleed
- Mastodon — Posted https://mstdn.social/@hostingpaper/117399957126640735




Discussion · coming soon
Be the first to join the thread when community discussion launches.