RC RANDOM CHAOS

86,644 FortiGate boxes still take the old password

The FBI says FortiBleed is still active, using 86,644 Fortinet credentials harvested months ago to plant admin accounts and feed ransomware crews.

· 3 min read
86,644 FortiGate boxes still take the old password

The FBI and Secret Service put a number on it on Tuesday: 86,644 working Fortinet device credentials across 194 countries, counted as confirmed compromises rather than an exposure estimate. That tally comes from SOCRadar and dates to June 19, 2026, when the FortiBleed campaign was first documented alongside Hudson Rock. The agencies are raising it again in October because the operators never stopped. They are still scanning internet-exposed FortiGate firewalls and SSL VPN gateways with credentials harvested months ago, and those credentials still work.

That credentials keep working months later is the core of SOCRadar’s framing: this is validated inventory, not a static dump. Devices breached in the spring remain in the actors’ working set. CISO Ensar Seker put it as exposed credentials not becoming harmless with age. If they stay valid, or if the operators already planted persistent accounts on the appliance, the box is still an entry point.

The campaign runs in five stages. It opens with wide reconnaissance to find exposed portals, then gets in through credential stuffing and password spraying built on prior leak dumps and infostealer logs. Once on a device, it deploys a Go tool the agencies call FortigateSniffer, which passively intercepts authentication traffic across 24 protocols and skims credentials and password hashes. The hashes go to a GPU cracking cluster running Hashmat and Hashtopolis, offline, on the operators’ own hardware. Cracked output feeds lateral movement: Active Directory enumeration, Kerberos validation, SMB authentication. The last stage pulls data off network shares and uses stolen session cookies to hold authenticated access.

The reason offline cracking pays off at this scale is Fortinet’s legacy SHA-256 password storage, which is cheap to attack with a GPU cluster. CISA’s guidance includes moving administrator credential storage to PBKDF2, the slow-hash answer to exactly this problem.

What sets FortiBleed apart from the usual edge-device story is what the operators do once they are in. Ben Bernstein at Huntress describes the access as silent: config files stolen, hashes cracked elsewhere, then a login that succeeds on the first try without a single failed-auth alert. An initial access broker would normally stay quiet and sell. These operators create new administrator accounts on the firewall, and in some cases delete the legitimate ones, which locks the real IT team out of their own device.

The agencies published the account names they have seen created, which doubles as a hunt list: adminin, fortiAdmin, forticloud-sync, fgtsecure, forticloud-tech, districtadmin, system_config, gttadmin, roadmin, adminsslvpn, my_admin, support_fortinet, fgtsec, and forti_support2, along with blend-in names like admin, itadmin, and IT_Manager. If any of those exist on your appliance and you did not create them, treat the device as compromised.

The lockout changes the incident math. When you cannot log into your own firewall, you cannot patch it. Bernstein’s point is that the operators count on exactly that: organizations will have to physically factory reset and rebuild the hardware, and the ransomware is timed to land in that window.

On the ransomware link, SOCRadar ties FortiBleed-derived access to the INC and Lynx ecosystem through operator overlaps and says it has confirmed at least 12 ransomware deployments from this access, with hundreds of endpoints encrypted. The same brokers have supplied access to Payload ransomware affiliates, which reads as a financially motivated supply chain feeding several ransomware brands rather than one.

The guidance from CISA, SOCRadar, and Huntress lines up. Treat possible exposure as a compromise rather than a patching problem. Restrict external management and remove internet-facing admin interfaces. Terminate active SSL VPN and administrative sessions. Rotate administrative and VPN credentials. Move administrator credential storage to PBKDF2. Enforce phishing-resistant MFA on all remote access. Review every local and API account on the appliance, and audit for accounts nobody created. Then investigate downstream, since the appliance is the way in and the damage happens deeper in the network.

If you find signs of compromise, the FBI and USSS ask that you isolate the affected devices, collect artifacts and logs before rebuilding, and report the incident to them.


#ad Contains an affiliate link.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.