The FBI and Secret Service are warning that FortiBleed remains an active credential-compromise campaign against internet-facing Fortinet firewall and VPN environments. CyberScoop reports that the campaign can lock administrators out of Fortinet systems and has been observed as an initial access path for ransomware affiliates.
That makes this more than another perimeter-device patch story. For small businesses, managed service providers, and government contractors, FortiBleed is a reminder that VPN and firewall credentials are effectively keys to the network edge. Once those keys are abused, defenders have to assume configuration changes, unauthorized accounts, API keys, lateral movement, and ransomware staging may already be in play.
Original reporting: CyberScoop: Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks. Primary advisory: FBI / U.S. Secret Service Cybersecurity Advisory PDF.
What happened
The advisory describes FortiBleed as a global campaign targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways. Attackers are reportedly using prior credential leaks, infostealer data, password spraying, credential stuffing, and credential material taken from compromised FortiOS devices. The government warning also notes that access has been connected to ransomware affiliates, including INC/Lynx and Payload.
The most operationally painful part is lockout. If attackers can create new administrator accounts, disable legitimate users, rotate passwords, or alter local configuration, the victim may lose control of the very appliance needed to restore secure remote access. That changes the response model from “reset a password” to “recover a potentially compromised control plane.”
Why this matters
VPN gateways and firewalls sit in a dangerous position: they are security controls, remote-access doors, identity chokepoints, and high-value administrative systems all at once. When adversaries obtain valid credentials for those systems, traditional detection can be weak because the activity may look like normal administrative access until configuration drift, new accounts, or lateral movement shows up elsewhere.
For SMBs and contractors, the risk is amplified by three realities:
- Edge devices are often internet reachable by design. Remote administration and SSL VPN portals are exposed more often than most organizations admit.
- Credential reuse is common. A single reused administrator password can bridge old leaks, infostealer logs, and live network access.
- Appliance logs are fragile. If logs are not forwarded before an incident, defenders may have limited visibility after an attacker changes configuration or deletes local evidence.
Defensive takeaways
1. Treat Fortinet credential exposure as an incident, not a maintenance ticket
If a Fortinet firewall or VPN was internet-facing and administrator or VPN credentials may have been exposed, do not stop at patching. Build a timeline, preserve logs, review configuration history, and hunt for follow-on access. Assume attackers may have tested credentials long before the alert reached your desk.
2. Remove public administrative access wherever possible
The strongest control is simple: do not expose firewall administration to the internet. Use trusted management hosts, local-in policies, management VPNs, jump boxes, or out-of-band administrative paths. If a management interface must be reachable, restrict it to known source addresses and monitor every login.
3. Reset credentials and terminate sessions deliberately
Rotate administrator and VPN credentials, terminate active sessions, and check whether attackers created new local users. Pay special attention to accounts with support-looking names, synchronization-themed names, or anything designed to blend into vendor operations.
4. Review API keys and automation accounts
Firewall API keys, integration accounts, and automation credentials are easy to overlook during password resets. Inventory all Fortinet-related API keys, remove unknown keys, rotate legitimate ones, and verify that automation still uses least privilege.
5. Hunt beyond the firewall
Valid VPN access is often just the first step. Review domain controller logs, privileged account activity, remote management tool use, endpoint alerts, suspicious SMB/RDP/WinRM traffic, new scheduled tasks, and signs of data staging. If ransomware affiliates received access, the goal may already have moved from edge access to internal monetization.
Bulwark Black assessment
FortiBleed is another example of a broader pattern: edge security appliances have become both initial-access targets and persistence platforms. The organizations that recover fastest will be the ones that already know which appliances are exposed, where their logs go, who can administer them, and how to rebuild them from a trusted baseline.
The practical move is to create an edge-device incident-response checklist now. Include exposed services, management access rules, backup configuration locations, log-forwarding destinations, credential owners, API keys, break-glass accounts, and rebuild procedures. When a campaign like FortiBleed hits, that preparation turns a chaotic lockout scenario into a controlled recovery operation.

