Back to Blog

FortiBleed VPN Gateway Lockouts: What the New Federal Warning Means

News By Ali Ghanavati

A fresh warning about compromised VPN gateways

The FBI and U.S. Secret Service warned on October 6 that an active global campaign known as FortiBleed continues to target internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Attackers have reportedly created unauthorized administrator accounts, altered or removed legitimate accounts and, in some cases, locked organizations out of their own equipment.

The joint advisory cites SOCRadar verification of more than 86,644 compromised devices across 194 countries. That is a reported, evolving count rather than a final independently audited total, but it illustrates the campaign’s reach. Independent reporting and fresh threat research published on October 7 also confirmed that the activity remains an active concern.

The central lesson is broader than one product: encrypting a VPN connection does not protect a gateway whose administrative credentials or configuration have been compromised. Organizations must treat remote-access gateways as sensitive identity systems, not merely networking appliances.

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts · FortiBleed Is Still Active, Locking Organizations Out · FBI, Secret Service add to warnings of FortiBleed credential stealing campaign | The Record from Recorded Future News

What FortiBleed is—and what it is not

FortiBleed is described as a credential-compromise campaign against organizational FortiGate devices. The documented methods include credential stuffing, password spraying and attempts to crack previously harvested password hashes. Attackers continue scanning exposed systems and trying credentials obtained during earlier incidents.

Fortinet’s analysis says the reported activity is not evidence of a newly discovered Fortinet vulnerability. The vendor instead points to credentials connected with previous incidents, brute-force activity, weak password practices and absent multifactor authentication. SOCRadar similarly characterizes credential reuse as a central part of the campaign.

This distinction matters. FortiBleed should not be described as a new zero-day, nor is there evidence in the reviewed sources that attackers broke VPN encryption. The warning also does not indicate that ordinary subscribers are compromised merely because they run a consumer VPN application. Its immediate focus is the enterprise equipment that organizations use to administer networks and provide remote access.

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts · Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog · FortiBleed Is Still Active, Locking Organizations Out

How stolen access can become a persistent compromise

An exposed management or VPN service gives attackers a place to test stolen, reused or predictable credentials. If a login succeeds, the intruder may not stop at accessing the gateway. The federal advisory says attackers have established persistence by creating new administrative accounts. Some have changed or deleted legitimate accounts, allowing malicious access to survive while defenders lose control.

A simplified attack path looks like this:

  1. An organization exposes a gateway or management service to the internet.
  2. An attacker successfully uses an old, reused or weak credential.
  3. The attacker creates another administrator account or changes the configuration.
  4. Legitimate administrators may be disabled or locked out.
  5. Access can then support deeper intrusion or be transferred to another criminal group.

The advisory connects initial-access brokers using this chain with affiliates associated with INC/Lynx and Payload ransomware. That connection does not mean every exposed gateway will lead to ransomware, but it raises the consequences of leaving suspicious access unresolved.

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts · FortiBleed Is Still Active, Locking Organizations Out

Why installing an update may not be enough

Software updates remain essential, especially when a device is unsupported or missing security fixes. However, patching does not automatically revoke a stolen password, remove an attacker-created account or reverse a malicious firewall rule. A gateway can therefore be fully updated and still remain under an intruder’s control if the compromise happened earlier.

Fortinet recommends upgrading supported devices, checking for unknown administrator and VPN users, and comparing the current configuration with a known-good copy. It also advises using stronger PBKDF2-based credential storage where applicable. Most importantly, the vendor says unauthorized configuration changes should be treated as evidence of compromise—not as a routine password-reset problem.

That means remediation must address both how the attacker entered and what changed after entry. Rotating credentials without ending active sessions, reviewing accounts and validating the configuration could leave another route open.

Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog · FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts

Priority checklist for administrators and small businesses

Changes to production gateways can interrupt remote work, so qualified administrators should plan them carefully. Based on the federal and vendor guidance, organizations should prioritize the following actions:

  1. Identify the equipment. Confirm whether the organization operates FortiGate or any other publicly reachable enterprise VPN or firewall appliance.
  2. Restrict management access. Remove the administrative interface from the public internet where possible. If exposure is operationally necessary, tightly limit which systems can reach it.
  3. End active sessions before rotating credentials. Terminate administrator and VPN sessions so an attacker cannot simply continue through an existing authenticated session.
  4. Replace exposed or reused passwords. Use unique credentials and ensure that the same password is not protecting email, cloud services or another gateway.
  5. Deploy phishing-resistant MFA. Protect both administrative and remote-access accounts wherever the platform supports it.
  6. Audit identities and configuration. Inventory administrator, VPN and API accounts, investigate undocumented entries and compare the device against a trusted backup.
  7. Review connected logs. Examine firewall, VPN, identity-provider and directory-service records for unfamiliar locations, new accounts, password changes and signs of movement into other systems.

If compromise is suspected, preserve relevant evidence and involve incident-response specialists. An immediate wipe may destroy logs needed to determine the attack’s scope. Organizations should also maintain an out-of-band recovery method in case normal administrator accounts are disabled.

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts · Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog

What employees and individual VPN users can do

Most readers will not administer a corporate firewall, but their behaviour can still reduce risk. A work VPN password should be unique and stored in a reputable password manager rather than reused on personal services. Reuse turns a breach elsewhere into a possible key for remote network access.

  • Deny and report any unexpected MFA request.
  • Never approve repeated prompts simply to make them stop.
  • Report sudden VPN lockouts or unsolicited password-reset messages.
  • Contact IT through a known channel if a login page, certificate warning or authentication process changes unexpectedly.
  • Do not assume that a successful VPN connection proves the gateway is securely administered.

The accompanying video is older conceptual background about SSL VPN and MFA rather than current incident guidance. Administrators should use documentation matching their deployed software version before changing a production configuration.

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts

VPN security extends beyond the encrypted tunnel

FortiBleed is a timely reminder that VPN security has several layers. Encryption protects data moving through a tunnel, but credentials decide who can enter, administrative controls determine who can change the gateway, and monitoring helps reveal when something has gone wrong.

The new warning does not justify panic among consumer VPN users, and it should not be exaggerated into a claim that VPN encryption has failed. It does justify urgent review by organizations operating exposed FortiGate equipment. Updates, unique credentials, strong MFA, restricted management access and configuration validation work together; none is a complete substitute for the others.

For organizations, the most important question is not only whether the gateway is patched. It is whether every administrator account, active session and configuration change can be trusted.

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts · Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog · FBI, Secret Service add to warnings of FortiBleed credential stealing campaign | The Record from Recorded Future News

A

Ali Ghanavati

Author at Valid VPN

More Reading

Related Articles

How Iran's Deep Packet Inspection Defeats Standard VPNs: Technical Reality and What Still Works
News

How Iran's Deep Packet Inspection Defeats Standard VPNs: Technical Reality and What Still Works

Iran's internet filtering infrastructure increasingly uses machine-learning-assisted deep packet inspection to identify and block commercial VPN protocols within seconds. This analysis explains how modern DPI detection works, why traditional VPN brands no longer offer reliable protection, and which obfuscation techniques remain viable—along with the genuine legal risks of VPN use in Iran.

Oct 10, 2026 Read More →

Ready to Bring Your Ideas to Life?

Let’s work together to create something useful, modern, and built for growth.

Get Your Free Quote
+13653879613 Get a Quote