PGH Networks

FBI Warns FortiBleed Credential Theft Is Still Active

October 7, 2026· PGH Networks Team· 5 min readBusiness & Tech Insights
FBI Warns FortiBleed Credential Theft Is Still Active

What happened

On Tuesday, the FBI and the U.S. Secret Service issued a joint warning that the credential-harvesting campaign known as FortiBleed is still active and still aimed at internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. According to reporting carried by feeds.feedburner.com, FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials, the campaign has already accumulated 86,644 sets of Fortinet device credentials.

The agencies describe the activity as exploiting reused or leaked credentials along with legacy SHA-256 password storage on affected devices. That combination is what makes this one unusual: the attackers are not necessarily breaking in through a single flashy software bug, they are collecting and replaying valid logins at scale. Specific affected firmware versions, indicators of compromise, and the full federal advisory text are details to verify directly against the FBI/USSS bulletin and Fortinet's own security advisories rather than assume from summaries, including ours.

people sitting on chair in front of computer

Why this matters for Pittsburgh small and mid-sized businesses

A FortiGate at the network edge is one of the most common firewall choices we see in offices of 10 to 200 people across Western Pennsylvania. Accounting firms in the South Side, law practices downtown, specialty medical groups in Monroeville, machine shops along the river corridors, defense suppliers in the Pittsburgh industrial belt, all of them frequently run a FortiGate with SSL VPN enabled so staff can get in from home or from a client site. That VPN is exactly what this campaign is after.

The uncomfortable part is what a valid firewall or VPN credential buys an attacker. It is not a malware alert on one laptop. It is a legitimate-looking session inside your network, from which an intruder can reach file servers, line-of-business databases, backup appliances, and on-prem domain controllers that still broker identity for your Microsoft 365 tenant. That is the standard pre-ransomware playbook, and it bypasses a lot of the detection logic that assumes attacks start on endpoints.

The compliance math is just as direct. For a CPA firm, unauthorized access to client tax data triggers FTC Safeguards Rule obligations and a very awkward conversation during busy season. For a medical practice, a VPN compromise that exposes ePHI becomes a HIPAA breach-assessment exercise with a 60-day notification clock. For a defense contractor, perimeter devices sit squarely inside your CMMC Level 2 boundary, and "we never rotated the firewall admin password" is not a finding you want in front of a C3PAO. SOC 2 auditors will likewise ask for evidence of credential rotation and MFA on remote access, and they will ask for dates.

Also worth naming: credentials harvested in a campaign like this get resold. Even if your device was exposed months ago and nothing has happened yet, the risk window is still open until you rotate.

What to do about it this week

  1. Inventory every internet-facing Fortinet device you own. Include the forgotten ones: a branch office, a warehouse, a secondary ISP circuit, a unit left in place after an office move. Confirm the model, firmware version, and whether SSL VPN is enabled and reachable from the internet. If you cannot produce that list in an hour, that gap is itself the finding.
  2. Patch to the current vendor-recommended firmware. Check Fortinet's published security advisories for the fixed releases that apply to your specific model and branch, and schedule the upgrade in a maintenance window this week rather than next quarter. Disciplined patch management on edge devices should be a standing process, not an incident response.
  3. Rotate every credential on and behind those devices. Local admin accounts, service and API accounts, SSO/LDAP bind accounts, SNMP strings, pre-shared keys, and every VPN user password. Assume anything stored on the device was harvested. Because legacy SHA-256 password storage is called out in the warning, old hashes should be treated as recoverable.
  4. Enforce MFA on all remote access, with no exceptions. Any VPN or admin account without a second factor is a single stolen password away from being an intruder. If you still have shared or vendor-maintained logins, that is where to start.
  5. Take the management interface off the public internet. Restrict administrative access to an internal VLAN or a hardened jump host, and limit VPN exposure with geo-fencing and source restrictions where your workflows allow it.
  6. Hunt for what may already have happened. Review VPN authentication logs for unfamiliar source IPs, impossible-travel logins, and successful authentications outside business hours. Check for unexpected local accounts, modified admin profiles, and config changes you cannot tie to a change ticket. Pair that with EDR telemetry on servers to catch post-access movement, and verify your backups are immutable and restorable.
  7. Document it. Record the devices checked, firmware applied, credentials rotated, and dates. Our advice to clients: close the loop by 2026-10-21 so you have a two-week paper trail your auditor, insurer, or prime contractor can actually use.

If your edge firewall is end-of-support or cannot run current firmware, replacement moves from "roadmap item" to "this month." A short technology roadmap conversation with your vCIO is the right place to decide between an in-place upgrade and a redesign.

How we help

PGH Networks manages firewalls, VPN access, and identity for small and mid-sized businesses across the Pittsburgh region, which means patching, credential hygiene, MFA enforcement, log review, and the documentation your HIPAA, SOC 2, CMMC, or FTC Safeguards obligations require are handled as ongoing work rather than fire drills. If you are not certain who last patched your firewall or rotated its admin password, that is the question worth answering today.

Call us at 724.888.7007 or reach out through the contact form and we will review your edge devices and remote access with you.

Share

Related reading

Call usBook a meeting