CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
CISA warns Fortinet customers of a sweeping campaign targeting FortiGate appliances, with 86,644 devices compromised. The threat actor uses a bespoke tool to spray login and password combinations to break into devices.
Intelligence analysis by Llama 3.3 70B

The FortiBleed campaign is a global attack targeting internet-facing Fortinet firewalls and VPN gateways, using methods like brute-force, dictionary attack, and credential stuffing.
Imagine you have a lock on your door, but you never changed the default combination. That's what happened with many Fortinet devices, making it easy for hackers to get in. They used a special tool to try many combinations at once, and now they have access to many devices.
Analysis
The Scale of the Breach
The FortiBleed campaign is a massive attack that has compromised 86,644 FortiGate devices, with the majority of compromised credentials being generic admin accounts and built-in Fortinet system accounts. This points to a widespread failure to rename default accounts or rotate factory credentials, giving the attacker a highly reliable target list.
The attack is built around a self-sustaining, two-step approach, where the threat actor attempts a curated list of leaked Fortinet passwords against devices across the internet, and then passively monitors network traffic to collect additional credentials.
The Impact on Organizations
The breach has significant implications for organizations, as it allows the threat actor to gain initial access to enterprise environments. The fact that organization-specific accounts account for 36.7% of the remaining breached credentials suggests that the attacker has also successfully compromised accounts created by the organizations themselves, possibly sourced from prior breaches where passwords were never changed.
The top three impacted sectors are telecom, government, and education, with the most exposures located in India, the U.S., Mexico, Colombia, and Thailand. This highlights the need for organizations to take immediate action to secure their devices and protect against the ongoing malicious activity.
Recommendations for Defense
CISA has outlined several recommendations to defend against the activity, including terminating all active SSL VPN and administrative sessions, resetting all Fortinet VPN and administrative passwords, and enforcing strong password policies. Organizations should also ensure the use of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials and remove weaker legacy hashes.
Additionally, organizations should review firewall, VPN, authentication, and domain controller logs for signs of suspicious actions, including unauthorized configuration changes. Enabling phishing-resistant MFA on all external gateways and administrative interfaces can also help reduce the attack surface and lock down management.
Key points
- 86,644 FortiGate devices compromised
- Generic admin accounts and built-in Fortinet system accounts make up the majority of compromised credentials
- Threat actor uses a bespoke tool to spray login and password combinations
- Organizations should take immediate action to secure their devices and protect against the ongoing malicious activity
If organizations take immediate action to secure their devices and protect against the ongoing malicious activity, they can prevent further breaches and minimize the impact of the attack. By following best practices, such as regularly rotating security credentials and enabling multi-factor authentication, organizations can reduce the risk of compromise.
The breach has already compromised a large number of devices, and the threat actor may have already gained access to sensitive information. If organizations do not take immediate action, they may be vulnerable to further attacks, which could have significant consequences, including data breaches and disruption of critical services.



