vuln-advisorytrade-pressNewsThe Broadside1 min read

FortiBleed still locks out users and feeds ransomware

Patch and password reset aren't enough when the attacker can disable accounts or change passwords.


TL;DR

The FBI and Secret Service warned Tuesday that FortiBleed, the credential-compromise campaign against Fortinet firewalls and VPN gateways, remains active and has been observed as an entry point for ransomware affiliates. SOCRadar verified more than 86,644 compromised devices across 194 countries when the campaign surfaced; its CISO says a later review counted 400,000 to 450,000 firewalls targeted in the wider operation, while cautioning the figures aren't directly comparable. The alert says attackers can disable accounts or change passwords, which forces remediation beyond standard patching and password resets.

The FBI and Secret Service put out a joint alert Tuesday saying FortiBleed, the credential-compromise campaign against Fortinet firewalls and VPN gateways, hasn't burned out. The alert says the attack chain "has been observed as an initial entry point for ransomware affiliates," and it names INC/Lynx and Payload among those receiving access from initial access brokers.

The scale has moved since the campaign surfaced this summer. SOCRadar verified more than 86,644 compromised devices across 194 countries when it first documented the operation. Its CISO, Ensar Seker, told CyberScoop a later review counted 400,000 to 450,000 firewalls targeted by the wider operation, while cautioning the earlier and later numbers aren't directly comparable. His conclusion: "the campaign is broader and more serious than we understood at the beginning."

The distinctive warning is about lockout. Attackers holding valid credentials can disable accounts or change passwords, which delays the victim's own remediation. The alert is explicit that affected organizations may need "remediation steps beyond standard patching and password resets." Agencies told Fortinet customers to remove public internet management access, reset credentials, enforce multifactor authentication, review firewall and VPN users for unauthorized changes, audit logs for lateral movement, and enable secure credential storage. They're also collecting IP addresses and attacker usernames from organizations willing to share indicators.


Published ·Deep Fathom

FortiBleed still locks out users and feeds ransomware — The Broadside