Files
llm-wiki/raw/articles/fortinet-fortibleed-credential-compromise-2026.md
2026-07-03 00:38:05 +09:00

5.7 KiB
Raw Permalink Blame History

source_url, ingested, sha256, discovered_from
source_url ingested sha256 discovered_from
https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices 2026-07-02 e6452c0ff7f9f6b0984cc13536a2fcf79712f397f860d599719444e7f0b2b3ee
platform channel_id channel_name message_id author_id posted_at message_excerpt
discord 1477793137064935675 tw 1522155439926808706 1477793167486226708 2026-07-02T08:22:17.159000000Z #tw digest highlighted VS Code 1.110 agentic browser tools, JADEPUFFER/Langflow agentic ransomware analysis, JAMSTEC Mesh Field Theory, and FortiBleed/FortiGate credential-harvesting context.

By | June 19, 2026

Situational Analysis

Fortinet is aware of reports of malicious cyber actors targeting Fortinet devices in a credential-harvesting campaign that a third-party firm has referred to as FortiBleed. Based on our initial analysis, we believe the activity involves threat actors reusing credentials from previous incidents (FG-IR-26-060, FG-IR-25-647) and employing brute-force techniques (as described in a March blog, “ Attacks at the Speed of AI ”) against devices with weak password hygiene and no multi-factor authentication (MFA).

Fortinet provided detailed guidance at the time of these advisories and we continue to strongly encourage all customers to ensure these remediation steps have been completed.

This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory.

Upon identifying the incident, we immediately began an investigation, including collaborating with relevant government agencies.

Was My Organization Affected?

Fortinet’s culture of proactive, transparent, and responsible product security disclosure is one of the many ways we show up as a responsible member of a larger cybersecurity ecosystem and demonstrate our commitment to helping customers make informed, risk-based decisions.

While this campaign is very specifically addressing Fortinet, the threat actor is being reported to have breached other vendor devices also with brute force credential harvesting. Fortinet has identified the potentially compromised systems, and we are proactively contacting impacted customers and will complete outreach in the days to come. While this problem is not unique to Fortinet, the below recommended guidance should be adopted by all concerned about potential impact.

To defend against this malicious cyber activity, Fortinet recommends that customers with impacted FortiGate appliances to immediately:

  1. Terminate all admin and VPN sessions and reset credentials. Terminate all active administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.
  2. Implement MFA on all administrator and VPN user accounts.
  3. Upgrade to latest versions of 7.4, 7.6, or 8.0. These versions supportPBKDF2 hashing of administrator credentials. Follow the guidance to remove older legacy password settings via set login-lockout-upon-weaker-encryption.
  4. Validate configuration. Review firewall and VPN users and other configuration for unauthorized changes. Preferably compare to a known good configuration. Pay particular attention to the addition of unrecognized accounts, such as “forticloud, fortiuser, fortinet-support, fortinet-tech-support,” etc.
  5. Check your logs. Look for unexpected administrator access from an unknown IP and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes.
  6. Reduce your attack surface and lock down management access. Restrict external management of your devices via trusted hosts (good), a local-in policy (better), or remove internet administration altogether (best).

Additional security best practices for administrator access and general hardening can be found in the Best Practices Guides.

If there is any evidence of unapproved modification of the configuration or other IoCs:

  • Treat the devices as compromised and follow the guidance here to recover.
  • Check for the creation of VPN users, unexpected password resets, or VPN from unexpected locations, which may indicate the actor has attempted lateral movement into the internal network.
  • If AD/LDAP integration is configured, it is important to treat this account as compromised and monitor your AD for its use for authentication elsewhere or the creation of additional accounts and monitor your network for lateral movement.

If you are a Fortinet customer and believe your internal network may have been compromised, please contact Fortinet support.

Fortinet diligently balances our commitment to the security of our customers and our culture of responsible transparency. We are continuing to investigate this situation and taking actionable steps with the security of our customers as our top priority. Our response and mitigation efforts remain ongoing.