WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

FBI: FortiBleed attackers can lock organizations out of their own firewalls

Low-angle view of tall server racks in a dim data hallAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

Details from an FBI investigation into the ongoing FortiBleed attacks reveal that victims could be locked out of their own firewall (a barrier that decides which network traffic may pass) even as attackers remain logged in. The operators were also found ranking organizations based on their revenue and network structure, the FBI said in an advisory .

After gaining access to a backend server left exposed by the attackers, the FBI and US Secret Service have shared new details of an operation that has already affected more than 80,000 devices worldwide. The server gave investigators a look at the infrastructure behind the operation, including systems used to process stolen credentials, crack password hashes, and identify potential targets.

“FortiBleed isn’t a vulnerability story anymore,” said Muhammad Yahya Patel , vCISO, cybersecurity advisor EMEA at Huntress. “It’s a persistence story. The credentials were taken months ago. The question every organization needs to answer is whether they’re still being used right now.”

Key facts

  • The operators were also — found: ranking organizations based on their revenue and network structure, the FBI said in an advisory

Sources & evidence