FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts
Description
FortiBleed is an ongoing global campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It exploits reused or leaked credentials and legacy SHA-256 password storage to harvest and crack authentication data at scale. Attackers gain access by scanning for exposed SSL VPN portals, performing credential stuffing and password spraying, and cracking stolen password hashes offline. Once inside, they create new administrative accounts for persistence and conduct Active Directory enumeration to expand access. Organizations may experience account lockouts due to attacker actions. The campaign acts as an initial-access broker with links to ransomware affiliates INC/Lynx and Payload, representing a significant medium-severity threat requiring immediate defensive measures.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FortiBleed is an active global credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It leverages reused or leaked credentials and legacy SHA-256 password storage weaknesses to harvest and crack authentication data using distributed GPU clusters. Attackers scan for exposed FortiGate SSL VPN portals, collect credentials via stuffing and password spraying, and crack stolen password hashes offline. After gaining access, they create new administrative accounts for persistence and conduct Active Directory enumeration to escalate and expand access. The campaign has compromised over 86,644 devices across 194 countries and causes lockouts by deleting or modifying existing accounts. It functions as an initial-access broker with observed connections to INC/Lynx and Payload ransomware affiliates, posing a significant threat to affected organizations.
Potential Impact
The campaign compromises Fortinet FortiGate firewalls and SSL VPN gateways by harvesting and cracking credentials, leading to unauthorized administrative access. This access allows attackers to create persistent accounts and perform Active Directory enumeration, potentially expanding their foothold within networks. Affected organizations may suffer account lockouts due to attacker modifications or deletions of legitimate accounts. The operation serves as an initial-access broker facilitating ransomware attacks by affiliates such as INC/Lynx and Payload, increasing the risk of subsequent ransomware incidents.
Defensive Guidance
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should immediately review exposed FortiGate SSL VPN portals and audit for unauthorized administrative accounts. Implement strong credential hygiene, including avoiding credential reuse and enforcing multi-factor authentication where possible. Monitor for unusual account activity and lockouts. Given the campaign's use of leaked credentials and password spraying, organizations should consider resetting credentials and enhancing password policies. Since this is an active campaign, timely detection and response are critical.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.ic3.gov/CSA/2026/261006.pdf"]
- Pulse Id
- 6ac679e7bbe47190f9ffce7a
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip103.27.186.156 | — | |
ip154.202.59.169 | — | |
ip45.154.12.132 | — | |
ip80.75.212.113 | — | |
ip85.11.187.8 | — | |
ip193.8.187.2 | — | |
ip45.227.254.210 | — | |
ip77.91.118.10 | — | |
ip193.8.187.42 | — | |
ip87.251.64.44 | — | |
ip185.136.15.66 | — | |
ip185.199.199.56 | — | |
ip5.155.250.158 | — |
Threat ID: 6ac74e5f2cdf04f656fcc1dc
Added to database: 10/08/2026, 08:03:43 UTC
Last enriched: 10/08/2026, 08:18:36 UTC
Last updated: 10/08/2026, 18:48:07 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.