86,644 FortiGate boxes still take the old password
The FBI says FortiBleed is still active, using 86,644 Fortinet credentials harvested months ago to plant admin accounts and feed ransomware crews.
The FBI and Secret Service put a number on it on Tuesday: 86,644 working Fortinet device credentials across 194 countries, counted as confirmed compromises rather than an exposure estimate. That tally comes from SOCRadar and dates to June 19, 2026, when the FortiBleed campaign was first documented alongside Hudson Rock. The agencies are raising it again in October because the operators never stopped. They are still scanning internet-exposed FortiGate firewalls and SSL VPN gateways with credentials harvested months ago, and those credentials still work.
That credentials keep working months later is the core of SOCRadar’s framing: this is validated inventory, not a static dump. Devices breached in the spring remain in the actors’ working set. CISO Ensar Seker put it as exposed credentials not becoming harmless with age. If they stay valid, or if the operators already planted persistent accounts on the appliance, the box is still an entry point.
The campaign runs in five stages. It opens with wide reconnaissance to find exposed portals, then gets in through credential stuffing and password spraying built on prior leak dumps and infostealer logs. Once on a device, it deploys a Go tool the agencies call FortigateSniffer, which passively intercepts authentication traffic across 24 protocols and skims credentials and password hashes. The hashes go to a GPU cracking cluster running Hashmat and Hashtopolis, offline, on the operators’ own hardware. Cracked output feeds lateral movement: Active Directory enumeration, Kerberos validation, SMB authentication. The last stage pulls data off network shares and uses stolen session cookies to hold authenticated access.
The reason offline cracking pays off at this scale is Fortinet’s legacy SHA-256 password storage, which is cheap to attack with a GPU cluster. CISA’s guidance includes moving administrator credential storage to PBKDF2, the slow-hash answer to exactly this problem.
What sets FortiBleed apart from the usual edge-device story is what the operators do once they are in. Ben Bernstein at Huntress describes the access as silent: config files stolen, hashes cracked elsewhere, then a login that succeeds on the first try without a single failed-auth alert. An initial access broker would normally stay quiet and sell. These operators create new administrator accounts on the firewall, and in some cases delete the legitimate ones, which locks the real IT team out of their own device.
The agencies published the account names they have seen created, which doubles as a hunt list: adminin, fortiAdmin, forticloud-sync, fgtsecure, forticloud-tech, districtadmin, system_config, gttadmin, roadmin, adminsslvpn, my_admin, support_fortinet, fgtsec, and forti_support2, along with blend-in names like admin, itadmin, and IT_Manager. If any of those exist on your appliance and you did not create them, treat the device as compromised.
The lockout changes the incident math. When you cannot log into your own firewall, you cannot patch it. Bernstein’s point is that the operators count on exactly that: organizations will have to physically factory reset and rebuild the hardware, and the ransomware is timed to land in that window.
On the ransomware link, SOCRadar ties FortiBleed-derived access to the INC and Lynx ecosystem through operator overlaps and says it has confirmed at least 12 ransomware deployments from this access, with hundreds of endpoints encrypted. The same brokers have supplied access to Payload ransomware affiliates, which reads as a financially motivated supply chain feeding several ransomware brands rather than one.
The guidance from CISA, SOCRadar, and Huntress lines up. Treat possible exposure as a compromise rather than a patching problem. Restrict external management and remove internet-facing admin interfaces. Terminate active SSL VPN and administrative sessions. Rotate administrative and VPN credentials. Move administrator credential storage to PBKDF2. Enforce phishing-resistant MFA on all remote access. Review every local and API account on the appliance, and audit for accounts nobody created. Then investigate downstream, since the appliance is the way in and the damage happens deeper in the network.
If you find signs of compromise, the FBI and USSS ask that you isolate the affected devices, collect artifacts and logs before rebuilding, and report the incident to them.
#ad Contains an affiliate link.
Keep Reading
fortinetUnpatched FortiMail flaw under attack
Fortinet warns of CVE-2026-104286, a critical FortiMail flaw under active exploitation that lets unauthenticated attackers write arbitrary files.
ciscoCisco warns of five NX-OS bugs that reach root
Cisco patched five critical NX-OS flaws allowing root code execution on Nexus 3000 and 9000 switches, plus regardless-of-config Cisco License bugs.
AI securityDeepSeek 4.1 Flash Looks Boring
DeepSeek 4.1 Flash matters because cheap long coding sessions change agent governance more than they introduce a new exploit.
Latest on the Wire
Full wire →- AI Development Shifts Undermine Low-Level Coding ExpertiseHacker News
- AI Security Gaps: Third-Party Agents Evade ControlThe Hacker News
- AI Uncovers Historical Secrets in 400-Year-Old ArchivesHacker News
- Anthropic AI Agents Target Government WebsiteSimon Willison
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.