Security researchers and national cybersecurity organizations are warning about FortiBleed Fortinet, a large-scale abuse campaign observed worldwide. The pattern centers on attackers attempting to gain access to Fortinet FortiGate firewalls and SSL-VPN environments using credentials that were previously stolen or leaked.
If your organization relies on Fortinet appliances, this is a prompt to verify whether any of your accounts or login details appear in known datasets and to assess whether suspicious activity may have occurred.
What researchers know about FortiBleed Fortinet
At the time of reporting, investigators did not find evidence that attackers were exploiting a new vulnerability. Instead, the observed abuse largely relies on reusing usernames and passwords that are already available from earlier compromises or data leaks.
Attackers then combine these credential sets with automated techniques such as brute-force attempts (trying many passwords automatically) and credential stuffing (reusing leaked logins on other systems). In several cases, researchers reported finding datasets containing valid usernames, email addresses, and passwords.
Based on current findings, the number of potentially affected Fortinet devices is estimated at around 30,000 to more than 70,000 globally. This does not automatically mean that every affected device suffered a successful compromise, but it indicates a broad campaign scope.
How attackers may move from access to deeper compromise
Investigators also describe a workflow that starts with initial access and then focuses on obtaining additional information. After attackers gain a foothold, they appear to intercept network traffic from Fortinet systems in order to capture login credentials.
Captured credentials can then be used for further access inside the organization, including access to internal networks. Because this sequence can vary by case, defenders are advised not to assume there was no impact until checks are completed.
How to check whether your organization is impacted
Organizations have already been contacted where researchers found relevant credentials. However, investigators note that the full extent of the campaign may not yet be fully mapped, meaning some affected organizations may not have been reached.
To reduce uncertainty, perform two complementary checks:
- Compare against known leaked datasets using the verification approach provided by the authorities.
- Run your own risk and impact assessment because the initial access outcome is not the same for every target.
In other words, even if you do not immediately see a match, you should still review your environment for signs of unusual logins or account activity.
High-priority actions to reduce risk
Since researchers cannot determine what follow-on actions attackers took after initial access for every organization, the recommended steps focus on reducing credential exposure and increasing visibility.
1) Reset passwords and other authentication methods
Consider resetting passwords and other authentication credentials for both administrative and user accounts. This includes SSH keys where applicable.
In addition, review and consider ending active SSL-VPN sessions and administrator sessions, especially if you detect suspicious authentication patterns.
2) Review logs for suspicious behavior
Next, investigate authentication and management activity. Focus on:
- Suspicious VPN logins
- Unexpected authentication attempts
- Unknown IP addresses or unusual source locations
- Uncharacteristic login times
When you review logs, include relevant systems and services such as Fortinet logs and any identity infrastructure you use, including Active Directory, LDAP, RADIUS, SSH, and other authentication logs. If you use network access controls, evaluate whether IP whitelisting is appropriate.
Where possible, enforce Multi-Factor Authentication (MFA) for administrative and user accounts to reduce the impact of stolen credentials.
3) Check for new or suspicious accounts
Attackers sometimes create or abuse accounts for persistence. Verify whether any new or unexpected accounts appear in your environment, including:
- Fortinet accounts
- Domain accounts
- Local accounts
- Service accounts
- SSH-related accounts and entries
If you find unfamiliar accounts, investigate when they were created, which systems they can access, and whether there is evidence of authentication from unexpected sources.
4) Assess SSH exposure on Fortinet devices
Review whether SSH access is enabled on your Fortinet appliances. Then evaluate whether direct SSH access from the internet is truly necessary.
Where possible, restrict administration to internal management networks or authorized source IP addresses. Reducing external exposure lowers the likelihood of brute-force attempts and makes detection easier.
5) Verify PBKDF2 usage for stored administrator hashes
Credential attacks often aim to compromise authentication data. Researchers advise checking whether your organization uses Password-Based Key Derivation Function 2 (PBKDF2) for storing administrator accounts.
They also recommend removing older and less secure hash methods according to Fortinet guidance. This helps ensure administrator credentials are better protected if password hashes are targeted.
Additional signals researchers observed
In multiple cases, investigators reported seeing attackers collecting packet captures from compromised Fortinet systems. This suggests that attackers may have been attempting to extract additional authentication information beyond what is already in leaked datasets.
Because this can vary by environment, treat unknown authentication artifacts—such as unusual traffic patterns or unexpected connections to management interfaces—as potential indicators and investigate accordingly.
What to do if you find evidence
If your checks suggest that you may be affected—either through dataset matches or suspicious activity—respond quickly and methodically:
- Contain access by terminating suspicious sessions and restricting management interfaces.
- Reset credentials and SSH keys for relevant accounts.
- Strengthen authentication with MFA and tighten access policies.
- Re-check logs after remediation to confirm the activity stops.
Where possible, involve your incident response team or external experts to validate scope and determine whether lateral movement occurred.
Stay updated while monitoring your environment
Researchers are continuing to follow developments related to FortiBleed Fortinet and may update guidance as new details emerge. In the meantime, prioritize active monitoring and apply the preventive measures above if you see indications of misuse.
If you are operating Fortinet FortiGate and SSL-VPN services, treating this as a practical credential hygiene and detection exercise can meaningfully reduce risk—even when there is no evidence of a brand-new vulnerability.
Bottom line: verify exposed credentials, review authentication and management logs, harden access controls, and strengthen administrator authentication. These steps help protect against attacks built on reused usernames and passwords.
Source: https://www.ncsc.nl/alerts/fortibleed-duizenden-fortinetsystemen-mogelijk-geraakt
