The FBI disclosed that threat actors are using the FortiBleed leak of plaintext FortiGate credentials to gain unauthorized VPN access, create rogue admin accounts, and lock out legitimate administrators. This underscores the need for robust access‑control policies, MFA, and continuous monitoring to satisfy audit‑readiness requirements.
ADTP Breach Watch· October 7, 2026· BleepingComputer
Attackers leveraged the FortiBleed leak—containing usernames and plaintext passwords for ~74k FortiGate firewalls—to access exposed SSL‑VPN portals. Using stolen credentials, they performed credential stuffing and password spraying, then cracked password hashes with GPU clusters. Once inside, they created new admin accounts, deleted or changed existing admin passwords, and locked out legitimate administrators, providing a foothold for ransomware affiliates such as INC/Lynx.
Why it matters for trust and compliance
The incident highlights a failure in identity‑and‑access management controls—specifically password hygiene, MFA enforcement, and privileged‑account monitoring—areas that continuous control‑assurance programs must evidence for audit readiness.
Implement continuous monitoring of privileged‑account changes to provide defensible audit evidence.
Adopt stronger password‑storage algorithms (e.g., PBKDF2) and enforce MFA to satisfy access‑control objectives across frameworks.