Circuit Wire — a daily news update from the Circuit.
The FBI and US Secret Service warned on Tuesday that an active campaign called FortiBleed is compromising internet-facing Fortinet firewalls and VPN gateways, and that some victims are being locked out of their own systems, according to a joint advisory.
The advisory cites SOCRadar verification of more than 86,644 compromised devices across 194 countries. Attackers use reused or leaked credentials and cracked legacy SHA-256 password hashes to get in. The agencies say affected organizations "may find themselves locked out of their systems" if attackers disable accounts or change passwords.
The operators work as initial access brokers, packaging access and selling it on. The advisory says the chain has been an entry point for affiliates of the INC/Lynx and Payload ransomware groups. It applies to all 16 critical infrastructure sectors.
The campaign came to light after its operators exposed their own backend server, which revealed how the group works, The Record reported. Attackers scan for exposed FortiGate SSL VPN portals, validate stolen logins, sort victims by revenue or network structure, and create new firewall accounts to keep their access. The Record cited SOCRadar research from July that put the number of affiliates scanning portals at more than 20, across more than 150 countries, with at least 12 organizations breached and hit with ransomware.
The advisory lists several steps for Fortinet users. These include restricting external management of devices or removing internet administration entirely, terminating all admin and VPN sessions, and resetting Fortinet VPN and administrative passwords. It also calls for phishing-resistant multifactor authentication on remote and administrative access, a review of firewall and VPN accounts for unrecognized users, and an audit of REST API keys.
The Record noted that CISA urged hardening of Fortinet devices in June after reports of credential exposure, and that the UK's National Cyber Security Centre has published its own advice following the global targeting of Fortinet firewalls and VPN gateways. The FBI and Secret Service ask that suspicious activity be reported to the Internet Crime Complaint Center or a local field office. Reporting is voluntary.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

