A Tuesday FBI security advisory warned of a known, ongoing global credential-compromise campaign called FortiBleed, which was first reported in June 2026 and involved internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.

FortiBleed is a known credential harvesting and brute force campaign that targets FortiGate devices with no multifactor authentication (MFA) and weak passwords. The campaign is extensive: SOCRadar has pointed to attacks on at least 86,644 devices across 194 countries. 

In the Tuesday advisory, the FBI advisory said that some victims of FortiBleed have reported getting locked out of their Fortinet devices, with the attackers either deleting or changing the password for original accounts on impacted systems. Furthermore, the FBI warned that the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates, including ones for INC/Lynx ransomware and Payload ransomware.

“During the initial intrusion, threat actors create new accounts not previously on the device,” according to the FBI’s advisory.  “In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment.”

The FBI said that attackers continue to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials. 

“The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale,” according to the advisory. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets.”

The advisory also listed various Indicators of Compromise (IoCs) in FortiBleed attacks, including IP addresses that were seen in victim logs, as well as a list of account names found on compromised devices.  

The advisory said organizations can reduce their attack surface and restrict management access by limiting external access to device management interfaces using trusted hosts, local-in policies, or, ideally, disabling internet-facing administration altogether. Companies can also terminate all active administrative and VPN sessions and reset Fortinet VPN and administrative passwords, particularly for internet-facing systems. They should also enforce strong password requirements. Finally, the FBI said organizations should enable phishing-resistant MFA for all remote-access and administrative accounts and ensure it is properly enforced across those systems.