FBI and Secret Service Warn of FortiBleed Attacks Locking Admins Out of Fortinet Devices
A joint alert from the FBI and Secret Service warns that the FortiBleed campaign has targeted over 86,000 Fortinet devices across 194 countries, completely locking out system administrators.

The Federal Bureau of Investigation (FBI) and the United States Secret Service have issued a joint advisory warning of an ongoing cyber campaign dubbed "FortiBleed." The campaign actively targets Fortinet networking equipment worldwide, posing a significant risk to organizational infrastructure.
Global Scope and Targeted Infrastructure
According to the alert, the FortiBleed campaign is actively impacting more than 86,000 Fortinet FortiGate firewalls and SSL VPN gateways located across 194 countries. The figures highlight the widespread nature of the threat confronting global network perimeters.
Tactics Used by Attackers
Threat actors behind the campaign employ specific methods to seize control of the targeted systems:
- Using Compromised Credentials: Attackers leverage stolen administrative credentials to gain initial unauthorized access to the devices.
- Creating Rogue Accounts: Once inside, the hackers establish new administrative accounts under their own control.
- Deleting Legitimate Accounts: The attackers subsequently delete pre-existing accounts, entirely locking legitimate network administrators (Admins) out of their own devices.
Why This Attack Matters
This campaign extends beyond standard data theft. By cutting off access to legitimate administrators, threat actors leave organizations unable to manage their own network boundaries. This total loss of control provides attackers with an open path to deploy ransomware or move laterally to infiltrate the target's internal network unrestricted.
Key Takeaways for IT and Security Teams
This advisory is critical for IT administrators, network security engineers, and organizations currently utilizing Fortinet FortiGate firewalls or SSL VPN solutions. Organizations relying on these devices are advised to closely inspect account activity, monitor system administrative privileges, and guard against unauthorized access configurations.
Source: SecurityWeek



