FortiBleed Is Still Active, Locking Organizations Out
On October 6, 2026, the FBI and the U.S. Secret Service published a joint Cybersecurity Advisory on FortiBleed, the active global credential compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.
If you defend or triage Fortinet exposure, this is the document to read in full; it adds field-response detail that changes how you should scope, hunt and remediate.
Below is what is operationally relevant right now: what has changed since the earlier reporting, the indicators to hunt on today, and the actions that actually close the gap. SOCRadar’s Threat Research Unit first documented FortiBleed in June, and we have folded the relevant background in where it helps you act.
The Three Things That Changed
1. Organizations are being locked out of their own firewalls.
This is the headline shift in impact. Alongside creating new admin accounts for persistence (T1136.001), the actors in some cases delete or change the passwords of legitimate original accounts (T1531, Account Access Removal). Defenders can find themselves shut out of their own FortiGate devices while the actor retains control and pivots internally.
Recovery now requires remediation steps beyond standard patching and password resets; if your runbook assumes a credential reset restores a clean state, it will fail in a lockout scenario. Confirm you have out-of-band administrative recovery for edge devices before you need it.
2. The downstream ransomware set is widening.
FortiBleed access has fed INC/Lynx, which earlier reporting tied directly to the campaign, and the advisory now lists downstream affiliates as currently including INC/Lynx ransomware and Payload ransomware.
The operative phrase is “currently including”: this is an Initial Access Broker (IAB) supply chain, so the roster of ransomware customers grows over time. Access harvested today can resurface as an encryption event weeks later under a brand not yet connected to FortiBleed. Treat any confirmed FortiBleed exposure as a potential precursor to multiple ransomware outcomes, not one.
3. The campaign is ongoing.
Attackers are still scanning internet-exposed Fortinet firewalls and authenticating with previously obtained credentials. The scale under discussion, more than 86,644 compromised devices across 194 countries, is a count of confirmed-compromised devices, not an exposure estimate. Devices breached months ago remain in the actors’ validated inventory.
The Attack Chain, Condensed
The joint advisory (JCSA-20261006-01) reconstructs the operation from artifacts the actors exposed on their own backend. For analysts building detections or scoping an intrusion, the pipeline is:
- Scan the internet for exposed FortiGate SSL VPN portals (T1595, T1190)
- Harvest credentials via credential stuffing (T1110.004) and password spraying (T1110.003), seeded from prior Fortinet leak dumps and infostealer logs
- Crack offline: exfiltrated hashes (T1003, T1041) run through a GPU cluster using Hashcat and Hashtopolis (T1110.002). The weakness enabling this is legacy SHA-256 password storage in FortiOS
- Enrich and prioritize: scripts filter out honeypots, map organizations, and rank targets by revenue and network structure; new admin accounts are planted for persistence
- Expand: with verified credentials (T1078), actors enter victim networks, run Active Directory enumeration (T1087), and spray for privileged accounts
- Package and sell: working VPN configs and target lists are handed to downstream actors, the IAB model
Worth noting for detection logic: this is commodity tradecraft, public credential dumps, off-the-shelf tooling and distributed cracking. The risk is scale and automation, not sophistication, which means your telemetry (auth anomalies, new account creation, AD enumeration bursts) is where this is catchable, not novel malware signatures.
Indicators to Hunt on Now
Treat IPs as historically observed infrastructure (cloud addresses get reassigned, so corroborate against current telemetry before blocking). The account names are the highest-signal starting point.
C2 and Supporting Infrastructure
- 45.154.12[.]132 – C2
- 154.202.59[.]169 – Proxy node
- 103.27.186[.]156 – Proxy node
- 45.155.250[.]158 – Beacon relay
- 193.8.187[.]2 – Facilitating the chain
- 193.8.187[.]42 – Facilitating the chain
- 85.11.187[.]8 – Facilitating the chain (Hashtopolis)
- Ports 4332, 4432 – Beaconing observed over HTTPS
Brute Force and Successful Auth Source IPs (June-July 2026)
- 104.28.155.27
- 185.136.15.43
- 185.136.15.66
- 185.199.199.56
- 193.8.186.33
- 45.227.254.210
- 77.91.118.10
- 80.75.212.113
- 87.251.64.13
- 87.251.64.16
- 87.251.64.17
- 87.251.64.44
- 66.175.220.111
Compromised Account Names
An unexpected account matching any of these is a strong intrusion indicator:
- adminin
- admin
- forticloud-tech
- gttadmin
- Technical_support
- my_admin
- forti_support2
- fortiAdmin
- fgtsecure
- districtadmin
- roadmin
- adminsslvpn
- support_fortinet
- forticloud-sync
- pakedge
- system_config
- itadmin
- IT_Manager
- fgtsec
Do not overlook two quieter vectors the advisory calls out.
- SSH: where the SSH port was left open on the firewall, actors may have exploited it directly. Include SSH access review in scoping
- REST API keys: API keys enable automated config, backup and monitoring on FortiGate, and a rogue key survives a password reset. Enumerate all keys, remove anything unknown, and refresh legitimate ones
What Actually Closes the Gap
The advisory’s mitigations apply to every Fortinet customer with an exposed gateway:
- Shrink the attack surface: restrict external management to trusted hosts (good), enforce a local-in policy (better), or remove internet-facing administration entirely (best)
- Terminate sessions and reset credentials: kill active admin sessions; reset all Fortinet VPN and admin passwords on internet-facing systems; enforce a strong password policy
- Enforce phishing-resistant MFA: on every remote access and administrative account and interface
- Validate configuration: against a known-good baseline, watching for unrecognized accounts
- Review logs: firewall, VPN, authentication and domain controller, for lateral movement, unusual access and unauthorized config changes
- Fix credential storage at the root: confirm FortiOS admin credentials use PBKDF2 and purge weaker legacy hashes, per Fortinet’s guidance (FortiOS v7.2.11+)
- Audit REST API keys: as above
For response, the advisory points to CISA’s Eviction Strategies Tool (Playbook-NG and COUN7ER) to assemble a TTP-mapped eviction plan, and standard sequencing: isolate compromised hosts, scope the intrusion before applying countermeasures, then harden. It also reiterates the standing guidance not to pay ransoms.
Check Your Exposure
SOCRadar’s free FortiBleed Check confirms whether your organization’s FortiGate or Fortinet VPN credentials appear in the active FortiBleed breach dataset. Enter a domain, IP or CIDR for an instant check, no signup required.

SOCRadar Free Tools: FortiBleed Check
Background: How the Operation Was Characterized
For context on the actors behind the access: FortiBleed is run as an initial access broker operation with a credential harvesting pipeline feeding a distributed GPU-cracking backend, surfaced after the operators exposed their own infrastructure.
Earlier research mapped a 20-plus-person operation tied to INC and Lynx, documented the internal target tracking and prioritization tooling, and detailed how the crew integrated commercial AI into reconnaissance, tool development and vulnerability research. That background explains why the IOCs and account name patterns above look the way they do, automated validation, honeypot filtering and revenue-based target ranking, and why the campaign scales the way it does.

