Back to all lessons
Awareness Lessons
4 days ago

FortiBleed: 86,000+ Credentials Compromised via Reused Passwords and Legacy Storage

The FortiBleed campaign exploits a combination of reused credentials, leaked authentication data, and outdated password storage mechanisms on internet-facing Fortinet FortiGate devices and SSL VPN gateways. Attackers are actively harvesting and cracking authentication data using GPU-accelerated offline cracking clusters, enabling lateral movement and data exfiltration at scale. This campaign highlights a critical failure at the intersection of credential hygiene, legacy system configuration, and inadequate monitoring of exposed network appliances. With over 86,000 credentials already compromised and the campaign still active, organizations that have not rotated credentials or updated configurations remain at immediate risk. The persistence of this threat underscores that patching alone is insufficient — credential hygiene and configuration hardening must accompany any remediation effort.

Tactical Insight

Immediate actions

  • Rotate all credentials for Fortinet FortiGate and SSL VPN devices immediately, especially if they are internet-facing.
  • Audit and disable any legacy password storage mechanisms on affected appliances and enforce modern hashing algorithms.
  • Verify that all FortiGate devices are running the latest firmware to eliminate known vulnerabilities being leveraged in this campaign.

Long-term improvements

  • Enforce Multi-Factor Authentication (MFA) on all VPN gateways and internet-facing management interfaces to reduce the impact of compromised credentials.
  • Maintain a continuously updated inventory of all internet-exposed network appliances and subject them to regular vulnerability assessments.
  • Implement network segmentation to restrict lateral movement opportunities if a perimeter device such as a firewall or VPN gateway is compromised.

Detection measures

  • Deploy behavioral monitoring and SIEM alerting to detect anomalous authentication attempts, credential stuffing patterns, and unusual traffic interception on perimeter devices.
  • Monitor for indicators of compromise (IoCs) associated with FortiBleed, including the Go-based traffic interception tool identified by the FBI and Secret Service.
  • Subscribe to threat intelligence feeds and FBI/CISA advisories to ensure timely awareness of active campaigns targeting your device types.