MediumII Cyber Warfare & Critical Infrastructure7 October 2026, Wednesday
FortiBleed campaign harvests login credentials from 86,000 Fortinet devices
The FBI and the US Secret Service warned on 7 October that the FortiBleed campaign is still active. According to The Hacker News, the attackers have harvested employee credentials for 86,644 Fortinet devices in 194 countries, and access is being sold to the INC/Lynx and Payload ransomware groups.
FortiBleed, detected in 2026, is a credential-harvesting campaign aimed at internet-facing FortiGate firewalls and SSL VPN gateways, the doors organisations use for remote access. The Hacker News reported on 7 October that, as of 19 June, the attackers had amassed working credentials for 86,644 devices in 194 countries. BleepingComputer said the figure stood at 73,932 firewall addresses when the campaign was first spotted. The Record reports that at least 12 organisations have been breached and encrypted with ransomware.
The campaign relies not on a new software flaw but on old and leaked passwords. BleepingComputer says the attackers use leaked passwords and infostealer logs, combined with two techniques: credential stuffing, which replays passwords leaked from other sites, and password spraying, which tries common passwords across many accounts. Captured password hashes are cracked on distributed GPU clusters with two open-source tools, Hashcat and Hashtopolis. According to The Hacker News, part of the weakness lies in an outdated SHA-256 password-storage method, and the FBI recommends moving administrator passwords to PBKDF2.
BleepingComputer reported on 7 October that the attackers create new administrator accounts, delete existing ones and lock organisations out of their own devices. The Record notes that the warning follows a CISA alert in June 2026 and earlier advisories from British authorities. The attackers left their own back-end server exposed, according to The Record, and The Hacker News describes the operation that law enforcement observed there in five stages. On 7 October the FBI and the Secret Service urged organisations to review all Fortinet accounts, reset passwords and terminate open administrator VPN sessions.
Talay assessment
Bottom line
FortiBleed shows that patching alone is not enough; the door stays open until leaked passwords are changed. A pool of 86,644 devices spread across 194 countries is a ready stock of entry points for ransomware groups. The most likely path is that new ransomware breaches using this access are disclosed in the coming weeks.
Likely effects
- Critical and public-sector networksNegativeWeeks
Municipal, hospital and industrial networks that rely on FortiGate VPN for remote access stay exposed to ransomware until passwords are reset.
- Cyber insuranceUncertain1–6 months
Insurers will scrutinise more closely the claims of organisations that failed to change passwords despite a known campaign.
- Networks in TürkiyeNegativeWeeks
A footprint of 194 countries may well include Türkiye; for organisations running FortiGate, resetting passwords and removing the management interface from the internet is urgent.
Possibilities, ranked
- 1New ransomware breaches disclosed60%
Using the access they have bought, the INC/Lynx and Payload groups encrypt new victims and post them on leak sites.
Watch: New victim listings on ransomware leak sites involving Fortinet access
- 2Mass password resets limit the damage30%
Under pressure from national cyber agencies, organisations reset passwords and the value of the access on offer drops quickly.
Watch: Additional CISA directives to federal agencies and updated Fortinet guidance
- 3The operators are caught10%
Traces from the exposed server lead to arrests or an indictment.
Watch: A US Justice Department indictment related to FortiBleed
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Devices with harvested credentials▼ 86,644
- Countries affected▼ 194
- Organisations hit by ransomware▼ at least 12