WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

Technician from behind in front of an open server rack with cablingAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

The FBI and Secret Service warned Fortinet users that FortiBleed, uncovered this summer, is a continuing threat. “In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware (software that locks up files and demands payment) affiliates.” Fortinet is a computer security company based in Sunnyvale, and its products and services include software.

FortiBleed, a credential compromise campaign targeting Fortinet firewalls (a barrier that decides which network traffic may pass) and VPN (a service that routes a connection through another network) gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday. “Affected organizations may find themselves locked out of their systems if threat actors (the person or group behind an attack) disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the alert states .

When it was first uncovered earlier this year, SOCRadar verified more than 86,644 compromised devices across 194 countries. The attackers can disable accounts or change passwords to lock users out with the access they gain, making standard password resets and patching insufficient, the government alert reads.

Sources & evidence