Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure7 October 2026, Wednesday

FortiBleed campaign harvests login credentials from 86,000 Fortinet devices

The FBI and the US Secret Service warned on 7 October that the FortiBleed campaign is still active. According to The Hacker News, the attackers have harvested employee credentials for 86,644 Fortinet devices in 194 countries, and access is being sold to the INC/Lynx and Payload ransomware groups.

Location: WASHINGTON

FortiBleed, detected in 2026, is a credential-harvesting campaign aimed at internet-facing FortiGate firewalls and SSL VPN gateways, the doors organisations use for remote access. The Hacker News reported on 7 October that, as of 19 June, the attackers had amassed working credentials for 86,644 devices in 194 countries. BleepingComputer said the figure stood at 73,932 firewall addresses when the campaign was first spotted. The Record reports that at least 12 organisations have been breached and encrypted with ransomware.

The campaign relies not on a new software flaw but on old and leaked passwords. BleepingComputer says the attackers use leaked passwords and infostealer logs, combined with two techniques: credential stuffing, which replays passwords leaked from other sites, and password spraying, which tries common passwords across many accounts. Captured password hashes are cracked on distributed GPU clusters with two open-source tools, Hashcat and Hashtopolis. According to The Hacker News, part of the weakness lies in an outdated SHA-256 password-storage method, and the FBI recommends moving administrator passwords to PBKDF2.

BleepingComputer reported on 7 October that the attackers create new administrator accounts, delete existing ones and lock organisations out of their own devices. The Record notes that the warning follows a CISA alert in June 2026 and earlier advisories from British authorities. The attackers left their own back-end server exposed, according to The Record, and The Hacker News describes the operation that law enforcement observed there in five stages. On 7 October the FBI and the Secret Service urged organisations to review all Fortinet accounts, reset passwords and terminate open administrator VPN sessions.

Talay assessment

Bottom line

FortiBleed shows that patching alone is not enough; the door stays open until leaked passwords are changed. A pool of 86,644 devices spread across 194 countries is a ready stock of entry points for ransomware groups. The most likely path is that new ransomware breaches using this access are disclosed in the coming weeks.

Likely effects

  • Critical and public-sector networksNegativeWeeks

    Municipal, hospital and industrial networks that rely on FortiGate VPN for remote access stay exposed to ransomware until passwords are reset.

  • Cyber insuranceUncertain1–6 months

    Insurers will scrutinise more closely the claims of organisations that failed to change passwords despite a known campaign.

  • Networks in TürkiyeNegativeWeeks

    A footprint of 194 countries may well include Türkiye; for organisations running FortiGate, resetting passwords and removing the management interface from the internet is urgent.

Possibilities, ranked

  1. 1
    New ransomware breaches disclosed60%

    Using the access they have bought, the INC/Lynx and Payload groups encrypt new victims and post them on leak sites.

    Watch: New victim listings on ransomware leak sites involving Fortinet access

  2. 2
    Mass password resets limit the damage30%

    Under pressure from national cyber agencies, organisations reset passwords and the value of the access on offer drops quickly.

    Watch: Additional CISA directives to federal agencies and updated Fortinet guidance

  3. 3
    The operators are caught10%

    Traces from the exposed server lead to arrests or an indictment.

    Watch: A US Justice Department indictment related to FortiBleed

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Devices with harvested credentials▼ 86,644
  • Countries affected▼ 194
  • Organisations hit by ransomware▼ at least 12

Sources

  1. The Record — FBI, Secret Service add to warnings of FortiBleed credential stealing campaign
  2. The Hacker News — FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
  3. BleepingComputer — FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins