A global credential-compromise campaign known as FortiBleed is actively targeting internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. Today, the
@FBI and
@SecretService issued a Joint Cybersecurity Advisory to warn organizations about this activity.
Threat actors are exploiting reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication at scale. More than 86,644 devices have been compromised across 194 countries, with some organizations locked out of systems.
We encourage organizations to review the advisory for TTPs and IOCs associated with this activity and implement our recommended mitigations.
👉
ic3.gov/CSA/2026/261006.pdf