FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, according to a joint FBI and U.S. Secret Service advisory.

FortiBleed targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The advisory cites SOCRadar, which has verified more than 86,644 compromised devices in 194 countries.
“Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system,” the agencies said.
“During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment,” the advisory reads.
For affected organizations, recovery may require “remediation steps beyond standard patching and password resets.”
“Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials,” the agencies warned.
The attackers run credential stuffing and password spraying attacks using earlier Fortinet leak dumps and infostealer logs. They pull password hashes from compromised devices and crack them on a GPU cluster with Hashcat and Hashtopolis.
“Cracked credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure,” the agencies wrote.
Once inside, the attackers enumerate Active Directory accounts and look for privileged users. The group then sells the access to affiliates of the INC/Lynx and Payload ransomware groups.
The advisory also includes IP addresses used by the attackers and usernames found on victim devices, along with mitigation steps.
The FBI and the Secret Service urge victims to report incidents, though reporting in response to this advisory is voluntary, and advise against paying ransoms.