The FBI and Secret Service have issued a warning regarding the ongoing FortiBleed campaign, which targets Fortinet FortiGate firewalls and SSL VPN gateways. This malicious operation exploits reused or leaked credentials and outdated SHA-256 password storage to gather and crack authentication data on a large scale. Initially discovered in June 2026 by SOCRadar and Hudson Rock, the campaign has compromised over 86,644 device credentials from 194 countries.

The attack involves several stages, beginning with reconnaissance to find exposed portals. Attackers use credential stuffing and password spraying tactics to gain access, followed by deploying a tool called FortigateSniffer to intercept authentication traffic. Cracked credentials are processed by a GPU-accelerated cluster, facilitating further network penetration and the exfiltration of sensitive data. Attackers create unauthorized administrative accounts and delete existing ones to maintain their hold on affected systems.

CISA has urged Fortinet users to adopt phishing-resistant authentication and rotate passwords to counter the threat. Additionally, the attack's link to the INC and Lynx ransomware operations suggests a broader and financially motivated ransomware supply chain. Organizations may face lockouts if attackers change or delete passwords of original accounts.

SOCRadar and Huntress experts stress the importance of treating potential exposure as a compromise. This includes enforcing multi-factor authentication, auditing systems for new accounts, and securing external management interfaces. The FortiBleed campaign highlights the need for vigilance against silent initial access tactics followed by aggressive takeovers, underscoring the importance of comprehensive security measures.