[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnTJAen_HT9xcXCgJwWlgedUdZiWHXD6Ys5POsuBfr_4":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"5f85b154-e4f2-4bbc-acd3-b4477ad665a4","FortiBleed Attackers Locking Victims Out of Fortinet Devices","fortibleed-attackers-locking-victims-out-of-fortinet-devices-0f8895","Attackers are creating new accounts and deleting existing ones and passwords to prevent legitimate access. The post FortiBleed Attackers Locking Victims Out of Fortinet Devices appeared first on SecurityWeek.","The FortiBleed campaign, active since June, targets internet-accessible Fortinet FortiGate firewalls and SSL VPN appliances. Attackers use compromised credentials and brute-force methods to gain access, then lock victims out by changing passwords and deleting accounts. The FBI and USSS have issued an advisory warning about this campaign, which has impacted approximately 86,644 devices globally.","Attackers are locking victims out of Fortinet devices by creating new accounts and deleting existing ones.","The FortiBleed credential-harvesting and access-broker campaign is still active, and attackers are locking organizations out of their Fortinet devices. Targeting internet-accessible Fortinet FortiGate firewalls and SSL VPN appliances, the campaign started in June. Fortinet’s analysis of the attacks revealed that the attackers were using previously compromised credentials and brute-force techniques to take over poorly protected devices. Within a week, the attacks hit over 86,000 Fortinet devices in 190 countries, and a Russian initial access broker was blamed for the campaign. Now, SOCRadar says it has confirmed the compromise of approximately 86,644 devices in 194 countries. The attackers are searching for accessible firewalls and using compromised credentials to take them over. “[This] is a count of confirmed-compromised devices, not an exposure estimate. Devices breached months ago remain in the actors’ validated inventory,” SOCRadar notes.Advertisement. Scroll to continue reading. In a joint advisory (PDF) released this week, the FBI and the US Secret Service (USSS) warn that the hackers have been locking organizations out of their Fortinet appliances by changing passwords and deleting accounts. “Some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment,” the advisory reads. The hackers have been observed scanning for exposed SSL VPN portals, harvesting credentials from infostealer logs and previous dumps, cracking hashed credentials offline, mapping the attack surface to evade honeypots, using verified credentials to compromise devices, and selling working VPN configs and target lists to other threat actors. The FBI and USSS recommend that affected organizations identify the compromised hosts, scope the intrusion, evict the attackers, harden protections to prevent additional threat actor activity, and report the intrusions. To reduce the attack surface, organizations should restrict management access, reset all Fortinet VPN and administrative passwords, implement phishing-resistant multifactor authentication (MFA), review firewall and VPN users and configurations, review and validate API keys, review logs for suspicious activity, and ensure credentials are stored securely. Related: Long-Running NPM Malware Campaign Accumulates 40,000 Downloads Related: Anthropic Introduces 3-Tier Cyber Verification Program for AI Access Related: Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies Related: FBI Blames Contractor’s Missed Patch for ShinyHunters Breach Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsFBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareApple to Tighten Full Disk Access Controls in macOS Amid AI RisksLong-Running NPM Malware Campaign Accumulates 40,000 Downloads8.8 Million Impacted by Data Breach at Denmark’s Central Person RegisterLinux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms Latest News Georgia Power, Alabama Power Data Breach Hits 400,000 AccountsQilin Ransomware Suspect Arrested in Japan, Extradited to GermanyHadrian Raises $40 Million to Expand Autonomous Offensive Security PlatformAdvantest Discloses Data Breach Months After Ransomware AttackChrome 155 Update Patches 247 VulnerabilitiesAnthropic Introduces 3-Tier Cyber Verification Program for AI AccessASOS Confirms Cyberattack, Data BreachWikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Ffortibleed-attackers-locking-victims-out-of-fortinet-devices\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F10\u002FFortinet.jpeg","2026-10-08T07:52:33+00:00","2026-10-08T08:00:24.261079+00:00",8,[18,21,23,26,29],{"name":19,"type":20},"FortiGate","product",{"name":22,"type":20},"SSL VPN",{"name":24,"type":25},"Fortinet","vendor",{"name":27,"type":28},"FortiBleed","threat_actor",{"name":30,"type":20},"Fortinet FortiGate","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":31,"icon":33,"name":34,"slug":35},null,"Threat Intelligence","threat-intelligence",[37,42,47,52],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":48},{"id":49,"icon":33,"name":50,"slug":51},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":53},{"id":31,"icon":33,"name":34,"slug":35},[]]