BREACH WATCH BRIEF High 🔑 Threat intel

FortiBleed Campaign Continues to Harvest FortiGate Credentials and Lock Out Administrators

Threat actors are still exploiting previously harvested FortiGate firewall and VPN credentials to gain admin access and lock out legitimate users. The activity highlights the need for MFA, credential rotation, and continuous monitoring to satisfy audit‑ready control assurance.

SeverityHigh
Type🔑 Threat intel
ConfidenceHigh
ReportedOct 9, 2026
Technology & SaaS Enterprises using Fortinet FortiGate firewalls or SSL‑VPNs across multiple sectors Stolen Credentials

What happened

Actors scan for exposed FortiGate firewalls and SSL‑VPNs, use stolen credentials to log in as administrators, and often disable accounts or change passwords, effectively locking out legitimate users. The FBI and Secret Service warned that the campaign now serves as an entry point for ransomware affiliates.

Why it matters for trust and compliance

  • The incident underscores the importance of continuous credential‑management controls and MFA enforcement—key elements of a defensible identity‑access program that can be demonstrated through audit‑ready evidence.
  • Enable MFA on all privileged and VPN accounts to block credential reuse.
  • Implement continuous monitoring of admin logins and automate session termination for anomalous activity.

Who is affected

Enterprises using Fortinet FortiGate firewalls or SSL‑VPNs across multiple sectors

Recommended actions

  1. Activate MFA for all privileged and remote‑access accounts.
  2. Rotate any credentials found in public leaks and inventory exposed devices.
  3. Deploy continuous monitoring for suspicious admin activity and automate isolation of compromised hosts.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.