FortiBleed Campaign Continues to Harvest FortiGate Credentials and Lock Out Administrators
Threat actors are still exploiting previously harvested FortiGate firewall and VPN credentials to gain admin access and lock out legitimate users. The activity highlights the need for MFA, credential rotation, and continuous monitoring to satisfy audit‑ready control assurance.
ADTP Breach Watch· October 9, 2026· DataBreachToday
SeverityHigh
Type🔑 Threat intel
ConfidenceHigh
ReportedOct 9, 2026
Technology & SaaSEnterprises using Fortinet FortiGate firewalls or SSL‑VPNs across multiple sectorsStolen Credentials
What happened
Actors scan for exposed FortiGate firewalls and SSL‑VPNs, use stolen credentials to log in as administrators, and often disable accounts or change passwords, effectively locking out legitimate users. The FBI and Secret Service warned that the campaign now serves as an entry point for ransomware affiliates.
Why it matters for trust and compliance
The incident underscores the importance of continuous credential‑management controls and MFA enforcement—key elements of a defensible identity‑access program that can be demonstrated through audit‑ready evidence.
Enable MFA on all privileged and VPN accounts to block credential reuse.
Implement continuous monitoring of admin logins and automate session termination for anomalous activity.
Who is affected
Enterprises using Fortinet FortiGate firewalls or SSL‑VPNs across multiple sectors
Recommended actions
Activate MFA for all privileged and remote‑access accounts.
Rotate any credentials found in public leaks and inventory exposed devices.
Deploy continuous monitoring for suspicious admin activity and automate isolation of compromised hosts.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.