The U.S. Federal Bureau of Investigation (FBI) and the U.S. Secret Service (USSS) confirmed on Tuesday that the FortiBleed credential harvesting campaign is still active. The ongoing threat specifically targets internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. This warning highlights that attackers are continuing to exploit these vulnerabilities to gain unauthorized access to enterprise network infrastructure.
Immediate Investigation Developments and Scope
Authorities revealed that the campaign has successfully amassed 86,644 Fortinet device credentials. The threat actors are leveraging reused or leaked credentials combined with legacy SHA-256 password storage mechanisms. This combination allows attackers to bypass standard security checks and maintain persistent access to vulnerable devices. The scale of credentials harvested indicates a sustained and methodical approach to compromising network perimeters.
FortiGate firewalls serve as critical security gateways for many organizations, managing traffic between internal networks and the internet. When these devices are compromised, attackers can potentially monitor data flows, intercept communications, or use the firewall as a pivot point to move laterally into deeper network segments. The SSL VPN gateways are equally critical, often serving as the primary entry point for remote workers and third-party vendors. Compromising these gateways effectively grants attackers a direct line of sight into sensitive corporate environments.
The use of legacy SHA-256 password storage is a key factor in the campaign's success. Many older Fortinet devices still rely on this hashing algorithm, which is more vulnerable to brute-force and rainbow table attacks compared to modern standards. When combined with credential reuse, where users employ the same password across multiple systems, the attack surface expands significantly. An attacker who obtains a credential from one source can often apply it to the firewall or VPN gateway, bypassing additional layers of security.
The FBI and USSS joint warning underscores the urgency for organizations to audit their Fortinet infrastructure. Companies using FortiGate firewalls and SSL VPN gateways should verify whether their devices are exposed to the internet and whether they are using legacy password storage mechanisms. Immediate action is required to mitigate the risk of unauthorized access, especially for organizations that have not yet patched their systems or rotated their credentials.
Why FortiBleed Matters for Network Security
The FortiBleed campaign represents a significant shift in how threat actors approach network infrastructure. Instead of targeting end-user devices or applications, attackers are focusing on the underlying security appliances that protect entire networks. This strategy allows them to achieve broader impact with fewer initial breaches. By compromising a single firewall or VPN gateway, attackers can potentially access thousands of devices and users behind that perimeter.
The commercial stakes are high for Fortinet and its enterprise customers. Fortinet devices are widely deployed across industries, including finance, healthcare, and government. A successful breach of these devices can lead to data exfiltration, ransomware deployment, or long-term espionage. The fact that the campaign remains active suggests that many organizations have not yet fully addressed the vulnerability or are unaware of their exposure.
Security analysts note that the reliance on legacy password storage is a common issue in the cybersecurity industry. Many organizations prioritize functionality and compatibility over security updates, leaving older devices running outdated protocols. This creates a persistent attack vector that threat actors can exploit over time. The FortiBleed campaign is a clear example of how legacy infrastructure can undermine modern security postures.
Organizations should prioritize credential rotation and password storage upgrades for their Fortinet devices. This includes migrating from SHA-256 to stronger hashing algorithms and ensuring that credentials are unique and not reused across other systems. Regular audits of internet-facing devices can help identify vulnerabilities before attackers exploit them. The FBI and USSS warning serves as a timely reminder that threat actors are actively targeting these infrastructure components.
Looking ahead, organizations should monitor for further updates from Fortinet regarding patches and mitigation strategies. The company may release new firmware updates or configuration recommendations to address the legacy password storage issue. Additionally, network traffic monitoring can help detect unusual activity from compromised firewalls or VPN gateways. Early detection of lateral movement or data exfiltration can limit the damage from a breach. The next few weeks will be critical for organizations to assess their exposure and implement remediation measures.
See Also
- Weibo's 3B AI Model Exposes Benchmark Flaws Shaking Industry Confidence
- Harvard Reveals Apple Watch Data — Menopause Impacts Sleep Quality Significantly


