Skip to main content

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts

0
Medium
Published: 10/07/2026 (10/07/2026, 16:57:11 UTC)
Source: AlienVault OTX General

Description

FortiBleed is an ongoing global campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It exploits reused or leaked credentials and legacy SHA-256 password storage to harvest and crack authentication data at scale. Attackers gain access by scanning for exposed SSL VPN portals, performing credential stuffing and password spraying, and cracking stolen password hashes offline. Once inside, they create new administrative accounts for persistence and conduct Active Directory enumeration to expand access. Organizations may experience account lockouts due to attacker actions. The campaign acts as an initial-access broker with links to ransomware affiliates INC/Lynx and Payload, representing a significant medium-severity threat requiring immediate defensive measures.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 08:18:36 UTC

Technical Analysis

FortiBleed is an active global credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It leverages reused or leaked credentials and legacy SHA-256 password storage weaknesses to harvest and crack authentication data using distributed GPU clusters. Attackers scan for exposed FortiGate SSL VPN portals, collect credentials via stuffing and password spraying, and crack stolen password hashes offline. After gaining access, they create new administrative accounts for persistence and conduct Active Directory enumeration to escalate and expand access. The campaign has compromised over 86,644 devices across 194 countries and causes lockouts by deleting or modifying existing accounts. It functions as an initial-access broker with observed connections to INC/Lynx and Payload ransomware affiliates, posing a significant threat to affected organizations.

Potential Impact

The campaign compromises Fortinet FortiGate firewalls and SSL VPN gateways by harvesting and cracking credentials, leading to unauthorized administrative access. This access allows attackers to create persistent accounts and perform Active Directory enumeration, potentially expanding their foothold within networks. Affected organizations may suffer account lockouts due to attacker modifications or deletions of legitimate accounts. The operation serves as an initial-access broker facilitating ransomware attacks by affiliates such as INC/Lynx and Payload, increasing the risk of subsequent ransomware incidents.

Defensive Guidance

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should immediately review exposed FortiGate SSL VPN portals and audit for unauthorized administrative accounts. Implement strong credential hygiene, including avoiding credential reuse and enforcing multi-factor authentication where possible. Monitor for unusual account activity and lockouts. Given the campaign's use of leaked credentials and password spraying, organizations should consider resetting credentials and enhancing password policies. Since this is an active campaign, timely detection and response are critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.ic3.gov/CSA/2026/261006.pdf"]
Pulse Id
6ac679e7bbe47190f9ffce7a

Indicators of Compromise

Ip

ValueDescriptionCopy
ip103.27.186.156
—
ip154.202.59.169
—
ip45.154.12.132
—
ip80.75.212.113
—
ip85.11.187.8
—
ip193.8.187.2
—
ip45.227.254.210
—
ip77.91.118.10
—
ip193.8.187.42
—
ip87.251.64.44
—
ip185.136.15.66
—
ip185.199.199.56
—
ip5.155.250.158
—

Threat ID: 6ac74e5f2cdf04f656fcc1dc

Added to database: 10/08/2026, 08:03:43 UTC

Last enriched: 10/08/2026, 08:18:36 UTC

Last updated: 10/08/2026, 18:48:07 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses