FortiBleed Is Still Active: A Post-Compromise Checklist for Firewalls and VPNs
The FBI and Secret Service say the FortiBleed campaign against Fortinet firewalls is still going. Here is a practical checklist for when you think a firewall or VPN gateway may already be compromised.
On this page · 5 sections
On Tuesday, the FBI and the US Secret Service warned that the FortiBleed campaign is still an active threat. It targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. SOCRadar originally verified more than 86,644 compromised devices across 194 countries.
The wider operation may be much bigger. SOCRadar's CISO told CyberScoop that a later investigation found more than 400,000 or 450,000 firewalls targeted. Counts differ between reports, so treat the numbers as a sign of scale rather than an exact total.
This post is not a deep dive into the campaign. It is a checklist for the question that matters if you run one of these devices: what do I do if I think someone already got in?
What the advisory says happened
According to The Register and CyberScoop, the attack chain looks like this:
- Attackers use credentials from earlier breaches and infostealer logs for credential stuffing and password spraying.
- They extract password hashes from compromised devices and crack them offline on GPU clusters. The campaign benefits from reused or leaked credentials and legacy SHA-256 password storage.
- They create new accounts that were not on the device before.
- In some cases they delete or change the original accounts, which locks the real owners out.
- Access has been passed to ransomware affiliates. The current evidence points to affiliates of INC/Lynx and Payload, and SOCRadar reported at least 12 confirmed ransomware attacks from FortiBleed as of July.
The key point from the advisory: affected organizations may need remediation "beyond standard patching and password resets." Patching alone does not remove an account an attacker has already created.
The checklist
1. Reduce exposure first
Before you clean up, stop new access.
- Restrict internet-facing management access, or remove it entirely. Admin interfaces should be reachable only from a management network or VPN.
- Terminate all active administrative and VPN sessions, so any attacker with a live session loses it.
- If you are already locked out, treat the device as compromised and escalate to your vendor support and incident response process.
2. Rotate credentials, and rotate the right ones
A password reset on one admin account is not enough. Think about everything the device can see or store.
- Reset passwords for all local admin and VPN accounts, not only the ones you suspect.
- Rotate anything stored on or reachable through the device: LDAP/AD bind accounts, RADIUS and API secrets, pre-shared keys, and service accounts.
- Use unique, long passwords that have never been used elsewhere. Reuse is the fuel for this campaign.
- Make sure the device uses modern credential storage. The advisory recommends enabling secure credential storage, because weak hashes can be cracked offline once extracted. Check your vendor's guidance for your firmware version.
- Remember that hashes may already be stolen. Rotating after the fact matters because it makes cracked hashes useless.
3. Review admin accounts
Attackers add accounts and delete real ones. Compare what is on the device with what you expect.
- List every administrator and local user. Look for accounts nobody on your team recognizes.
- Check creation dates and last-login times against your change records.
- Look at the privileges of each account, including API users and trusted hosts.
- Note any missing accounts too. A deleted original admin is as suspicious as a new unknown one.
- Keep a record (screenshots or exports) before you change anything, so you can support an investigation.
4. Look for anomalies in VPN and admin logins
Your logs tell you whether the credentials were actually used.
- Look for logins from unusual countries, hosting providers or IP ranges, and logins at odd hours.
- Look for many failed logins followed by a success. That pattern suggests spraying or stuffing.
- Look for one account logging in from several places in a short time.
- Check for configuration changes, new admin sessions, and new VPN users or policies.
- Follow the trail inward. The advisory advises reviewing logs for lateral movement, so check what VPN users did after they connected: internal scans, new RDP or SMB connections, and use of admin tools.
- Make sure logs are sent to a separate system. If the device is compromised, local logs can't be trusted.
If you find indicators, the agencies would like to hear about them. They are asking for IP addresses and usernames used by the attackers. Reporting is voluntary, and the FBI and USSS advise against paying ransoms.
5. Enforce MFA, preferably phishing-resistant
Stolen passwords are the entry point, so a password should never be enough on its own.
- Require MFA for every VPN user and every administrator.
- The advisory specifically mentions phishing-resistant MFA, such as FIDO2 security keys or passkeys. SMS codes and push approvals are better than nothing but weaker.
- Do not leave exceptions for "temporary" accounts, vendors or service logins. Those are the ones attackers look for.
- Test it. Confirm that an account without MFA can't connect.
6. Hunt for ransomware precursors
Because access brokers sell this foothold, assume the clock is running.
- Check for new accounts in Active Directory, unexpected remote-management tools, and disabled security software.
- Verify that backups are offline or immutable, and test a restore.
- Have your incident response contacts ready before you need them.
A short version to keep
- Close management access to the internet.
- Kill active sessions.
- Rotate every credential the device touches.
- Audit admin and VPN accounts, both new and missing.
- Review logs for odd logins and lateral movement.
- Enforce phishing-resistant MFA.
- Report indicators and prepare for ransomware.
Takeaway
FortiBleed is a reminder that firewalls and VPN gateways are high-value targets, and that the weak point is often credentials rather than a software bug. Patching still matters, but it can't undo an account that is already in place. Checking who has access, and making that access harder to steal, is what closes the door.
Note: details come from public reporting on an advisory that is still developing. Check the FBI/USSS advisory and Fortinet's own guidance for the latest indicators and fixes.
Sources
Enjoyed this? Get the next post by email
One email when something new is up. No spam, and you can unsubscribe anytime.
Comments
No comments yet. Start the conversation.