Skip to main content
Defentria

Ransomware

The FBI warns that attacks on FortiGate using stolen passwords are ongoing, and open the door to ransomware

The FBI and the US Secret Service warn that the FortiBleed campaign is still active: it breaks into FortiGate firewalls and VPNs with leaked or weak passwords and sells the access to ransomware groups. It isn't a new flaw: updating isn't enough, you need to change passwords and enable MFA.

By Defentria editorial teamPublished 3 min read

Fortinet — Vendor of the targeted devices (this is not a new vulnerability)

Front of a Fortinet FortiGate 100D firewall installed in a network cabinet, with its green lights on and yellow fibre cables above it
Image: webernetz on Flickr (CC BY 2.0, cropped)

In 30 seconds

  • The FBI and the US Secret Service warned on 6 October that the FortiBleed campaign against FortiGate firewalls and VPNs is still active.
  • It doesn't exploit a new flaw: it uses leaked, reused or weak passwords, and mainly targets devices without MFA, according to Fortinet.
  • According to the FBI, the attackers create their own admins and, in some cases, delete or change the legitimate ones, locking the company out of its own firewall.
  • The access is sold to ransomware groups: the advisory names INC/Lynx and Payload. SOCRadar has verified more than 86,644 compromised devices in 194 countries.

Does this affect me?

It affects you if your company has a FortiGate firewall with the VPN or the admin interface reachable from the internet, especially if passwords haven't been changed in months or there's no MFA. That's the typical setup of an SME with remote work. Being up to date doesn't protect you: the attack gets in with passwords. No Spanish victims have been publicly confirmed.

What happened

On 6 October 2026, the FBI and the US Secret Service published a joint advisory (JCSA-20261006-01) on FortiBleed, a campaign that, according to the document, is still active against Fortinet FortiGate firewalls and their internet-facing VPN gateways.

The advisory describes it as a global credential-theft campaign: the attackers get in with passwords reused or leaked in earlier incidents, or guess them by trying common passwords, and take advantage of the fact that some devices store admin passwords with an old method that can be cracked. With that access, they create new admins, extract more credentials and move into the company's internal network.

Fortinet had already spoken out in June. On its security blog it made clear that "this is not a new Fortinet vulnerability" and that the activity combines credentials reused from earlier incidents with brute-force attacks against devices with weak passwords and no multi-factor authentication (MFA).

What we know

  • Scale: the FBI advisory notes that security firm SOCRadar has verified more than 86,644 compromised devices in 194 countries.
  • Lockouts: according to the FBI, in some cases the attackers delete the original accounts or change their password, and the company is locked out of its own firewall.
  • Ransomware: the advisory says those behind it sell the access to other criminals and names two ransomware groups that have already used it: INC/Lynx and Payload.
  • Warning signs: the FBI publishes names of accounts created by the attackers, which imitate support or admin accounts (for example, "support_fortinet", "forti_support2" or "itadmin").
  • Updating isn't enough: the FBI warns that regaining control may require more than applying patches and changing passwords.

What we don't know yet

  • Whether Spanish companies are affected. Neither the FBI nor Fortinet gives figures by country, and SOCRadar's report offers no figures for Spain.
  • How many companies have been locked out or hit by ransomware as a result of this campaign. The advisory gives no figures.

Why it matters

Most firewall alerts are about a software flaw and a patch. Not this one: the attack walks in through the front door, with a username and password. A fully updated device is still exposed if its VPN accepts a leaked password and doesn't ask for a second factor.

And whoever gets in rarely stays put. According to the FBI, the campaign works as a broker that sells access to ransomware groups: the firewall is only the first step.

What it means for an SME

In a 20-person company with remote work, the FortiGate VPN is often the only way into the office files. It's common that:

  • the IT provider set it up years ago and nobody has changed the passwords since;
  • several employees, or the provider itself, share the same user;
  • MFA isn't required because "it's more convenient that way".

If an employee's password leaked from another service and they reuse it on the VPN, that's exactly the kind of access this campaign is looking for.

What your company should do this week

  1. Ask your IT provider whether you have a FortiGate with the VPN or the admin interface reachable from the internet. If the admin interface doesn't need to be open, have them close it or restrict it.
  2. Change the passwords for the VPN and the firewall admins, and end open sessions, as the FBI and Fortinet recommend.
  3. Enable MFA on the VPN and the admin accounts. It's the measure that makes this attack hardest. Our guide to MFA (in Spanish) explains how to raise it with your team.
  4. Ask them to review the firewall's admins and remove any account nobody recognises. If one turns up, treat the device as compromised.
  5. Ask them to update FortiOS to a recent version that stores passwords with the more secure method Fortinet recommends (PBKDF2). It doesn't replace the previous steps, but it closes one of the routes the campaign uses.

Sources

  1. FBI and US Secret Service — «FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts» (joint advisory JCSA-20261006-01, 6 October 2026)Primary source
  2. Fortinet PSIRT — «Analysis of Reported Credential Compromise of FortiGate Devices» (Carl Windsor, 19 June 2026)Primary source
  3. SOCRadar — «FortiBleed: SOCRadar's Investigation into 86,644 Compromised Fortinet Firewalls» (16 June 2026, updated 3 September 2026)
  4. BleepingComputer — «FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins» (Bill Toulas, 7 October 2026)

Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.