Patching Was Never the Fix: FBI and Secret Service Say FortiBleed’s 86,644 Stolen FortiGate Credentials Now End in Lockouts and Ransomware
On 6 October 2026 the FBI and the U.S. Secret Service published joint advisory JCSA-20261006-01, “FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts.” The headline numbers: more than 86,644 compromised FortiGate devices across 194 countries, verified by SOCRadar, in what the agencies describe as an active global credential-compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Attackers are still scanning exposed firewalls with previously stolen credentials, victims are discovering they have been locked out of their own appliances, and the access is being wholesaled onward — the advisory names INC/Lynx and Payload ransomware affiliates as downstream customers of the initial-access pipeline.
The single most important sentence in the advisory is the one that reframes the entire campaign: FortiBleed “exploits reused or leaked credentials and a legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale.” There is no FortiBleed CVE. There is no firmware that fixes it. The campaign industrializes two unglamorous weaknesses — passwords that appear in earlier leak dumps and infostealer logs, and FortiOS credential hashes stored in a fast, unsalted-legacy SHA-256 form that a GPU cluster eats for breakfast — into a credential supply chain with its own reconnaissance, cracking, validation and resale stages.
An end-to-end operation, exposed by its own opsec failure
The advisory’s technical section reads like a post-mortem the attackers wrote about themselves, because in a sense they did: the operators unintentionally exposed their own backend server, and the open directory laid out the whole pipeline. Automated scripts scan the internet for reachable FortiGate SSL VPN portals. Credential-stuffing and password-spraying runs draw on prior Fortinet leak dumps and infostealer logs. Dumped FortiOS user databases and session tokens flow into a GPU-accelerated cracking cluster orchestrated with Hashcat and Hashtopolis. Cracked credentials are enriched, filtered against honeypots, mapped to organizations and prioritized — reportedly by revenue and network structure — before being validated and used. Persistence is created directly on the appliance: new administrative accounts are added to the firewall, and in some intrusions the original accounts are deleted or their passwords changed, which is how a victim ends up locked out of hardware it owns.
The advisory publishes the defenders’ cut of that backend: infrastructure IPs (including a C2 at 45.154.12.132, proxy nodes and a Hashtopolis host), a table of addresses observed brute-forcing or successfully authenticating, and a list of rogue account names found on victim systems — adminin, fortiAdmin, forticloud-sync, fgtsecure, pakedge, districtadmin, system_config, roadmin, Technical_support, adminsslvpn, my_admin, support_fortinet, fgtsec, among others. With verified credentials the operators move into the LAN: Active Directory enumeration, more password spraying, lateral movement — and then the packaging stage, with working VPN configurations and target lists sold to downstream actors. The MITRE ATT&CK mapping in the advisory runs from resource development (rented GPU infrastructure, T1583) through impact (account access removal, T1531).
From June dataset to October ransomware on-ramp
The trajectory matters. In mid-June 2026 researcher Volodymyr “Bob” Diachenko surfaced a dataset of valid FortiGate administrative and SSL VPN credentials; CISA followed on 18 June urging Fortinet customers to harden devices after reports of credential exposure covering roughly 74,000 devices, and Fortinet published its own analysis on 19 June. Four months later the count is 86,644 and the campaign has graduated from credential harvesting to lockouts and ransomware staging. The June guidance — terminate sessions, reset passwords, enforce phishing-resistant MFA, move to PBKDF2 storage — is repeated almost verbatim in the October advisory, which tells you how many organizations did not act on it. Credentials, unlike vulnerabilities, do not age out when you ignore them; they get cracked, validated, enriched and resold.
Note the structural parallel with the week’s other edge-infrastructure stories: SonicWall’s pre-auth SSRF on the SMA1000 login portal and the NetScaler SAML flaws are bugs you patch. FortiBleed is a condition you remediate — sessions, passwords, hashes, accounts, API keys — and the advisory is blunt that remediation goes “beyond standard patching and password resets” once the attackers hold admin on the box.
What to do
- Lock down management access in tiers: trusted hosts at minimum, a local-in policy preferably, no internet administration ideally. The advisory ranks these good, better, best — and every internet-facing management interface is currently being scanned with valid credentials, not exploits, so a WAF will not see it.
- Terminate all admin and VPN sessions and reset every Fortinet password, then enforce phishing-resistant MFA on all remote and admin accounts. Assume session tokens harvested alongside passwords are live; a password reset without session termination leaves the attacker logged in.
- Confirm PBKDF2 storage for administrator credentials and purge legacy hashes (Fortinet documents the enforcement path for FortiOS 7.2.11 and later). Fast SHA-256 hashes are the reason stolen databases convert to plaintext at GPU speed.
- Hunt for the advisory’s IOCs: the published IPs, the rogue account names, and unknown REST API keys. Validate firewall and VPN user lists against a known-good configuration, review auth and domain-controller logs for lateral movement, and treat any unfamiliar API key as compromise until proven otherwise.
- If you find evidence of intrusion, scope before you evict — the advisory points responders at CISA’s Playbook-NG/COUN7ER eviction tooling — and report to IC3 or a local FBI or Secret Service field office. Do not pay ransomware; the agencies repeat the standing guidance that payment guarantees nothing.
Verification note: the 6 October 2026 publication date, the JCSA-20261006-01 identifier, the 86,644-devices/194-countries figures (SOCRadar-verified), the reused-credentials-plus-legacy-SHA-256 mechanism, the ongoing scanning with previously obtained credentials, the lockout mechanism (deleted/changed original accounts, T1531), the exposed-backend discovery, the Hashcat/Hashtopolis GPU cluster, the honeypot filtering and revenue-based prioritization, the INC/Lynx and Payload ransomware connection, the infrastructure IPs, the rogue account names, the REST API key warning, the PBKDF2/FortiOS 7.2.11 guidance, and the full mitigation list were read directly from the FBI/USSS joint advisory PDF (TLP:CLEAR, 11 pages, retrieved from ic3.gov). The June timeline — Diachenko dataset, CISA 18 June alert (~74,000 devices), Fortinet 19 June analysis — is from secondary reporting and the vendors’ own publications as cited below. We tested nothing, contacted no agency, and reproduced only a sample of the IOCs; defenders should work from the advisory itself.
Sources:
- FBI / U.S. Secret Service — Joint Cybersecurity Advisory JCSA-20261006-01, FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts (6 October 2026, PDF)
- The Hacker News — FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials (7 October 2026)
- The Record — FBI, Secret Service add to warnings of FortiBleed credential stealing campaign (7 October 2026)
- CISA — CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure (18 June 2026)
- Fortinet PSIRT Blog — Analysis of Reported Credential Compromise of FortiGate Devices (19 June 2026)