BREACH WATCH BRIEF High 🔑 Breach

FBI Warns FortiBleed Credential Leak Enables Lockout of FortiGate VPN Administrators

The FBI disclosed that threat actors are using the FortiBleed leak of plaintext FortiGate credentials to gain unauthorized VPN access, create rogue admin accounts, and lock out legitimate administrators. This underscores the need for robust access‑control policies, MFA, and continuous monitoring to satisfy audit‑readiness requirements.

SeverityHigh
Type🔑 Breach
ConfidenceHigh
ReportedOct 7, 2026
Technology & SaaS Technology SaaS providers Enterprises exposing FortiGate VPN gateways Stolen Credentials

What happened

Attackers leveraged the FortiBleed leak—containing usernames and plaintext passwords for ~74k FortiGate firewalls—to access exposed SSL‑VPN portals. Using stolen credentials, they performed credential stuffing and password spraying, then cracked password hashes with GPU clusters. Once inside, they created new admin accounts, deleted or changed existing admin passwords, and locked out legitimate administrators, providing a foothold for ransomware affiliates such as INC/Lynx.

Why it matters for trust and compliance

  • The incident highlights a failure in identity‑and‑access management controls—specifically password hygiene, MFA enforcement, and privileged‑account monitoring—areas that continuous control‑assurance programs must evidence for audit readiness.
  • Implement continuous monitoring of privileged‑account changes to provide defensible audit evidence.
  • Adopt stronger password‑storage algorithms (e.g., PBKDF2) and enforce MFA to satisfy access‑control objectives across frameworks.

Who is affected

Technology SaaS providers Enterprises exposing FortiGate VPN gateways

Recommended actions

  1. Restrict external access to FortiGate SSL‑VPN portals and terminate all active VPN sessions.
  2. Enforce MFA for all administrative accounts and upgrade password hashing to PBKDF2 or stronger.
  3. Deploy continuous logging and alerting on admin account creation, deletion, and password changes.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.