Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The FBI and U.S. Secret Service issued a joint alert on October 6, 2026, elevating FortiBleed from a vendor incident to a national security priority. The campaign does not exploit a zero-day vulnerability but a credential-management flaw in Fortinet devices: passwords stored with legacy SHA-256 hashes, vulnerable to offline cracking at industrial scale. The stakes exceed credential theft; authorities confirm FortiBleed serves as an initial entry point for ransomware affiliates, with over 86,644 devices compromised across 194 countries.
- The October 6, 2026 alert confirms FortiBleed is an "active and ongoing" threat, not concluded or declining.
- Attackers used a 45-GPU infrastructure to crack legacy SHA-256 hashes offline, generating a global dataset of valid credentials.
- After a FortiOS firmware upgrade, passwords remain in SHA-256 format until an administrator manually logs in; only then do they migrate to PBKDF2.
- Fortinet explicitly denied this is a new vulnerability; the compromise stems from credential reuse, brute force, and obsolete storage.
The Government Alert: "Locked Out of Their Systems"
The joint FBI and Secret Service advisory, reported by CyberScoop, clearly defines the operational consequences for victims. Once threat actors obtain administrative access, they can disable legitimate accounts or change passwords, locking organizations out of their own systems. The source states verbatim: "Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets."
This wording is significant: authorities signal that the standard response—patching and password resets—is insufficient. The problem lies in the persistence of legacy hashes which, even after a firmware upgrade, require human interaction to trigger the algorithmic migration.
The alert also confirms the FortiBleed attack chain has been observed as an "initial entry point for ransomware affiliates," naming specific groups: INC/Lynx and Payload. The link between credential theft and ransomware deployment is not an analytical hypothesis but a documented finding by investigative authorities.
"The strongest data point is the scale: SOCRadar verified over 86,644 compromised devices in 194 countries, with subsequent estimates indicating 400,000-450,000 firewalls targeted by the broader operation"
The Technical Mechanism: SHA-256 vs. PBKDF2
The core of the vulnerability lies in a design flaw in FortiOS password migration. Devices running firmware prior to versions 7.6.1, 7.4.8, or 7.2.11 stored administrative credentials with SHA-256 hashes, an algorithm now considered inadequate for offline password protection. The corrected versions introduced by Fortinet adopt PBKDF2, a key derivation function more resistant to brute force.
The critical issue, documented by Hoodline based on Fortinet information, is that the firmware upgrade does not automatically convert existing hashes. Passwords stored with SHA-256 "remain that way until each administrator successfully logs in after the upgrade." Only a manual post-upgrade login triggers hash regeneration with PBKDF2. Organizations that updated hundreds of devices without verifying subsequent logins left thousands of crackable hashes in the field.
Attackers exploited this window with industrial automation. Bitsight documents an offline cracking infrastructure composed of 45 GPUs, capable of processing SHA-256 hashes at speeds that make compromise of insufficiently complex passwords trivial. The result: more than 73,000 internet-exposed FortiGate firewalls had verified exposed administrator credentials, and approximately 50% of all internet-reachable FortiGate devices may be affected.
Post-Exploitation Tools: From Credential to Ransomware
Bitsight's analysis identifies specific tools observed in the phases following initial compromise. Chisel, a TCP/UDP tunnel over HTTP, and Neo-reGeorg, a web shell with SOCKS proxy capabilities, appear in the "Post-Exploitation Tools Observed" table. Both facilitate lateral movement and access stabilization in perimeter networks. EternalBlue rounds out the picture, suggesting operators exploit legacy vulnerabilities in internal Windows systems once past the firewall.
This sequence confirms the operational model described in the FBI alert: FortiBleed is not an end in itself but enables broader chains. Compromise of the VPN/firewall perimeter—achieved with administrative privileges—exposes the entire internal network to subsequent ransomware deployment. Government confirmation with specific affiliate names (INC/Lynx, Payload) shifts the risk from theoretical to documented.
Ensar Seker, CISO of SOCRadar, summarizes the operational evolution: "What stands out for me is that FortiBleed is still an active threat, and attackers are using stolen credentials to access the exposed Fortinet devices, create new administration accounts, and in some cases, lock the real owners out." The creation of additional administrative accounts complicates remediation and prolongs persistence even after resetting the original credentials.
Immediate Actions
Priority actions derive directly from the available technical documentation:
- Verify that every administrator has performed a manual login after the FortiOS upgrade to trigger the SHA-256 → PBKDF2 migration; the mere presence of the correct firmware does not guarantee protection.
- Check for unauthorized administrative accounts created after the upgrade date, an indicator of compromise flagged by SOCRadar.
- Inspect logs for access from anomalous IP addresses or suspicious authentication patterns, particularly preceding the creation of new admin accounts.
- Assess the internet exposure of the FortiGate management panel: reducing the attack surface limits the use of stolen credentials obtained via offline cracking.
Fortinet has published specific guidance on its PSIRT platform, reiterating that "This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory." The vendor statement, while serving the legitimate interest of delimiting responsibility, provides independently verifiable technical guidance on hash migration management.
The Hidden Migration Problem
FortiBleed exemplifies an underrated category of operational risk: the migration defect. When a vendor fixes a cryptographic mechanism, the implicit assumption is that the patch solves the problem. Here the opposite occurs: the patch introduces the protective capability but does not activate it without human interaction, creating an exploitable temporal gap.
Attackers have demonstrated they understand this gap better than defenses. The investment in 45 GPUs for offline cracking indicates a strategy of capitalizing on the credential dataset over long time horizons, not opportunistic attacks. The estimate of 400,000-450,000 targeted firewalls—subsequent to the initially verified 86,644—suggests hash collection preceded the campaign's public disclosure by months.
The absence of a CVE associated with FortiBleed, consistent with Fortinet's denial, makes automatic prioritization difficult in CVE-driven vulnerability management pipelines. Tools that depend on CVE identifiers for triage will not flag this threat, despite it being active and having documented ransomware impact.
The dossier does not specify whether a single threat actor or multiple groups are using the same credential dataset, nor the exact start date of hash collection. June 2026 represents the first publicly documented temporal reference. No infrastructure overlaps linking FortiBleed operators to other known campaigns have emerged to date.
Why the October 6 Alert Changes the Game
Government confirmation transforms FortiBleed from vendor intelligence to a national security priority. The implication for organizations is not merely technical but one of governance: the presence of Fortinet devices in critical infrastructure—hosted by entities operating under sectoral regulations—triggers reporting and response obligations that previous vendor advisories did not.
The most relevant takeaway for security operations is that posture verification can no longer rely on patching checklists. It requires active auditing of credential management on perimeter devices, with specific attention to incomplete algorithmic transitions. FortiBleed demonstrates that the failure point is not always in new code, but in the persistence of old code masked by a successful update.
Sources
- https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/
- https://hoodline.com/2026/10/fortibleed-hackers-breach-86-000-firewalls-lock-out-admins-in-194-countries/
- https://kudelskisecurity.com/research/fortinet-fortibleed-global-compromise-active-exploitation-of-fortinet-vulnerabilities
- https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices
- https://www.bitsight.com/blog/security-alert-fortibleed-fortinet-vpn-credentials-firewall-exposed
- https://kudelskisecurity.com/research/fortinet-fortimail-path-traversal
- https://kudelskisecurity.com/modern-ciso-blog/from-ot-visibility-to-resilience
- https://kudelskisecurity.com/company/career
- https://kudelskisecurity.com/modern-ciso
- https://kudelskisecurity.com/research-blog
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.