The FBI and US Secret Service say the FortiBleed credential campaign against Fortinet firewalls is still running, and attackers are now deleting or changing admin accounts so that victims are locked out of their own devices. For UK organisations that treated the NCSC’s June alert as a password-reset exercise, this is a prompt to go back and check properly.
What happened
On 6 October 2026 the FBI and the US Secret Service published a joint cyber security advisory, JCSA-20261006-01, warning that FortiBleed operators are still going after FortiGate firewalls and SSL VPN gateways exposed to the internet. The advisory, which The Register and Infosecurity Magazine reported on 7 and 8 October, relies on SOCRadar figures putting the tally of compromised devices above 86,644, spread over 194 countries.
The new element is lockout. According to the agencies, intruders create fresh administrator accounts on compromised appliances and, in some cases, delete or re-password the original ones. Victims can then find themselves unable to log in to the very device that sits between their network and the internet, a situation the advisory says may demand work “beyond standard patching and password resets”.
The agencies also link the campaign to ransomware. Initial access brokers using FortiBleed credentials have supplied network access to affiliates of INC/Lynx and Payload, and The Register notes that SOCRadar counted at least 12 ransomware attacks linked to the campaign by July.
FortiBleed is not new to UK defenders. On 18 June 2026 the NCSC issued an alert after a leaked credential database surfaced, noting signs that UK organisations may have been affected and urging Fortinet customers to investigate rather than simply rotate passwords.
The technical picture
FortiBleed is not a single software flaw. It is a credential-harvesting and access-broking operation whose workings became visible when the operators accidentally left their own back-end server exposed, giving researchers an unusually complete view of the pipeline.
The chain, as the FBI and USSS describe it, runs in five broad stages:
- Discovery. Automated scanning finds exposed FortiGate SSL VPN portals.
- Access. Credential stuffing and password spraying draw on earlier Fortinet leak dumps and infostealer logs.
- Cracking. Password hashes and user databases taken from compromised devices are fed to a rented GPU cluster running Hashcat, orchestrated by Hashtopolis.
- Triage. Recovered credentials are validated and ranked, with scripts discarding honeypots and prioritising victims by revenue and network structure.
- Exploitation and sale. Rogue admin accounts provide persistence, attackers enumerate Active Directory and spray internal accounts, and working VPN configurations are packaged for sale.
Two details deserve emphasis. First, the agencies point to weak legacy SHA-256 storage of administrator credentials as one reason cracking works at scale, and they ask organisations to confirm that PBKDF2 is in use, following Fortinet’s guidance for FortiOS 7.2.11 and later. Second, the advisory publishes a list of account names seen on victim devices, including plausible-looking entries such as fortiAdmin, forticloud-sync and support_fortinet, chosen to blend in with genuine vendor or support accounts. It also flags REST API keys as a quiet persistence route and recommends removing unknown keys and refreshing legitimate ones.

Why it matters for UK organisations
FortiGate appliances are a staple of UK networks, from local authorities and schools to manufacturers and managed service providers. The NCSC’s June alert was explicit that UK organisations running SSL VPN on Fortinet edge devices should investigate for malicious activity and watch their networks closely.
The October advisory changes the risk calculation in two ways. Lockout turns a confidentiality problem into an availability one: losing administrative control of a perimeter firewall during an incident badly constrains your response options. The reported ransomware link, meanwhile, means a compromised VPN credential is now a realistic precursor to an extortion event rather than a theoretical exposure.
There is also a timing issue. Organisations that reset passwords in June but did not hunt for rogue accounts, stored configurations or API keys may still be carrying a foothold. The NCSC warned at the time that “changing credentials alone may not be sufficient” once an attacker has persistence, and the new advisory bears that out.
Expert view
Edge devices remain the soft underbelly of many otherwise well-run estates. In my experience, the firewall is often the one asset nobody owns from a monitoring perspective: it generates logs that are rarely forwarded to the SIEM, its local accounts sit outside identity governance, and its management interface is left reachable from the internet “temporarily” for a supplier.
What stands out here is how commercial the operation is. Honeypot filtering and revenue-based prioritisation are the behaviours of a business optimising its sales pipeline, not opportunists. John Strand of Black Hills Information Security, quoted by Infosecurity Magazine, said that the quiet, long-term persistence FortiBleed enables worries him more than noisy intrusions, and I agree: the lockout cases are the ones you notice.
When we assess perimeter devices, local admin accounts with generic names and no MFA are a recurring finding. Treat any account on the list published by the agencies as hostile until proven otherwise, and remember that attackers will simply choose new names next time.
What to do now
- Check exposure first. Use the SOCRadar or Hudson Rock FortiBleed checkers the NCSC pointed to, and confirm every listed device is yours.
- Hunt on the device. Compare current configurations with a known-good baseline, review all local and API accounts against the advisory’s name list, and search logs for the published IP addresses.
- Preserve, then rebuild. If you find compromise, isolate the device, collect logs and configurations, and factory reset it as the NCSC advises. Report to the NCSC and consider an NCSC-assured incident response provider.
- Look beyond the firewall. Review domain controller and authentication logs for spraying and enumeration, and check other edge devices that share credentials.
- Lock down management. Remove internet-facing administration altogether where possible, or restrict it to trusted hosts. This is core to the Cyber Essentials firewalls control.
- Enforce strong authentication. Apply phishing-resistant MFA to every VPN and admin login, replace generic and reused passwords, and enable PBKDF2 hashing. This maps to Cyber Essentials user access control.
- Keep it current. Run supported firmware and retire end-of-life appliances under Cyber Essentials security update management.
- Plan for lockout. Ensure you have out-of-band console access and offline configuration backups, so losing admin access does not stall your response.
Bottom line
FortiBleed has moved from leaked passwords to locked-out administrators and ransomware entry. If your organisation runs Fortinet SSL VPN and your June response stopped at a password reset, schedule a proper compromise assessment of those devices now, and treat perimeter appliances as monitored, governed assets rather than set-and-forget boxes.
Sources
- FBI and US Secret Service: FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts
- NCSC: Advice following global targeting of Fortinet firewalls and VPN gateways
- The Register: FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
- Infosecurity Magazine: FBI and Secret Service Warn of FortiBleed Lockout Threat