
Federal Agencies Warn That FortiBleed Hackers Are Locking Network Admins Out of Firewalls
An ongoing global credential operation has compromised over 86,000 network gateways, locking out system owners and feeding corporate access directly to ransomware gangs.
8 Oct 2026
Federal law enforcement agencies are warning that an aggressive hacking campaign is locking network administrators out of their own security hardware. The operation, known as FortiBleed, targets internet-connected Fortinet FortiGate firewalls and virtual private network gateways around the world.
A joint advisory from the FBI and the U.S. Secret Service highlights the global scale of the campaign. Security monitoring group SOCRadar confirmed that more than 86,644 devices have been compromised across 194 countries. The breaches touch all 16 designated critical infrastructure sectors, with over half of the affected machines located in India, the United States, Taiwan, Mexico, and Turkey.
The intrusions do not rely on a software flaw in the firewalls. Instead, the attackers use credentials leaked in past breaches, lists harvested by info-stealing malware, and automated guessing attacks to break through remote login portals that lack secondary verification.
After gaining an initial foothold, the hackers extract stored password hashes, which are scrambled digital fingerprints of passwords. They run these hashes through large networks of graphics processing units to crack the real passwords offline. This cracking process is made easier when firewalls rely on legacy SHA-256 storage instead of newer protection methods.

Investigators were able to examine the attack chain in detail because the operators made an operational mistake. The hackers accidentally exposed their own backend server, allowing researchers to see the automated tools, target rosters, and sorting scripts running behind the scenes.
The exposed files reveal an operation designed like a corporate sales pipeline. Automated scripts test credentials, discard fake decoy systems, and evaluate targeted companies by their organizational structure and annual revenue so higher-value targets can be prioritized.
The operators function as access brokers, packaging working logins to sell to other cybercriminals. Authorities confirmed that compromised firewalls have already served as entry points for ransomware syndicates, naming the INC, Lynx, and Payload ransomware groups as active buyers.
Once inside, the intruders maintain their grip by creating fresh administrator profiles. In many cases, they delete original accounts or change the existing passwords. This leaves legitimate technology teams completely locked out of their devices and unable to run standard recovery procedures.
Authorities advise affected organizations to sever remote management interfaces from the public internet immediately and end all active connections. Defenders should also switch administrator password hashing to PBKDF2, review internal logs for hidden accounts, and require multifactor authentication on every remote portal.
BleepingComputer , Cybersecurity Dive , Security Affairs , Help Net Security