FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices
What happened
The latest advisory also identifies Payload ransomware (software that locks up files and demands payment) among the groups connected to access obtained through the campaign. The FBI and US Secret Service are warning about ongoing FortiBleed attacks against internet-facing Fortinet FortiGate (enterprise firewalls) firewalls (a barrier that decides which network traffic may pass) and SSL (the encryption that secures a connection to a website) VPN (a service that routes a connection through another network) gateways in a joint advisory ( PDF ) published on October 6, 2026.
Hackread.com first covered FortiBleed in June based on findings from Hudson Rock and researcher Volodymyr “Bob” Diachenko. The campaign was later linked to INC Ransom and Lynx ransomware activity, showing how exposed FortiGate access could move from credential abuse into ransomware operations.
SOCRadar has now shared additional findings with Hackread.com on the campaign’s infrastructure, credential-cracking operation and indicators. According to the latest research , more than 86,644 devices across 194 countries have been compromised, with some victims finding themselves locked out after attackers changed passwords or removed existing accounts.
Sources & evidence
- Hackread Reporting source
FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices ↗
https://hackread.com/fbi-fortibleed-campaign-active-fortigate-devices/