
FBI Confirms FortiBleed Still Harvesting FortiGate Credentials via Go Tool and GPU Cracking
FortiBleed remains active with 86,644 compromised FortiGate credentials obtained through credential stuffing and a custom Go sniffer. The campaign reveals persistent gaps in Fortinet device hardening and credential management across global networks. Initial access is being packaged for ransomware operators.
FortiBleed operates in five stages: reconnaissance of exposed SSL VPN portals, initial access via reused credentials and legacy SHA-256 hashes, deployment of the Go-based FortigateSniffer binary, offline cracking on Hashmat and Hashtopolis clusters, and final exfiltration of network shares plus session cookies. Attackers create new administrative accounts while deleting originals to lock out defenders and maintain persistence. Overlaps with INC and Lynx ransomware indicate the operator functions as an initial access broker packaging access for downstream buyers.
Procurement records and prior Fortinet incidents show repeated failure to enforce PBKDF2 credential storage or phishing-resistant MFA on internet-facing appliances despite CISA directives. The 86k credential count, validated through SOCRadar telemetry as of June 2026, exceeds typical IAB hauls and points to sustained scanning of legacy devices rather than a single zero-day. Official FBI and USSS statements emphasize ongoing activity but omit independent confirmation of Russian attribution beyond language markers in tooling.
Operational risk centers on lateral movement into Active Directory environments once firewall access is obtained. Organizations must audit logs for new accounts listed in the advisory, rotate all FortiGate credentials, and segment VPN termination from core networks. Without these steps, the same access paths will be resold and reused for ransomware deployment within weeks.
Next indicators will likely appear in fresh infostealer marketplaces and ransomware affiliate forums as the broker liquidates remaining validated sessions.
FBI: Additional batches of 15,000+ FortiBleed credentials will appear on Russian-language forums within 45 days.
Sources (3)
- [1]The Hacker News Report(https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html)
- [2]SOCRadar FortiBleed Disclosure(https://socradar.io/fortibleed-campaign-fortinet/)
- [3]CISA Fortinet Advisory(https://www.cisa.gov/news/2026/06/fortinet-vpn-hardening)