On 6 October 2026 the FBI and U.S. Secret Service published a joint advisory stating that FortiBleed — an ongoing global campaign against internet-facing FortiGate firewalls and SSL VPN gateways — remains active. Advisory CSA 261006 describes attackers reusing leaked or recycled credentials, abusing legacy SHA-256 password storage, and in some cases locking legitimate administrators out by disabling accounts or changing passwords. That means “reset passwords and patch” may not restore control by itself.
Since summer 2026 Fortinet has analysed the activity as a mix of credential stuffing, brute force against weak accounts without MFA (multi-factor authentication), and reuse from earlier incidents (FG-IR-26-060, FG-IR-25-647). SOCRadar and others have reported tens of thousands of compromised devices across many countries; exact counts vary by source, but the scale — mass exposure of edge gear — is consistent. The advisory stresses attackers continue scanning the internet for Fortinet appliances using already stolen logins.
What raises severity in October is the lockout signal: organisations may find they can no longer access their own firewall with existing accounts after attackers create new administrators or change policy. FBI/USSS also warn the FortiBleed chain has been observed as initial access for ransomware affiliates, including names such as INC/Lynx and Payload in reporting cited by CyberScoop. That moves FortiBleed from “credential leak news” to prioritised incident response.
For Nordic organisations FortiGate is common as VPN and partner-facing edge. Many historically left admin interfaces internet-reachable “temporarily.” The advisory recommends restricting or removing external administration, enforcing MFA, rotating credentials, reviewing VPN and firewall users for unauthorised changes, hunting logs for lateral movement, and moving to PBKDF2 credential storage on FortiOS 7.4, 7.6, or 8.0 per vendor guidance.
What IT and security leads should do now
Terminate suspicious sessions, rotate all administrator passwords and API keys, and verify MFA on every privileged account. Remove internet administration unless strictly required; use jump hosts or Zero Trust instead. Compare configuration and user lists to pre-incident backups; attackers often add hidden admin accounts. Treat lockout indicators as full appliance compromise: isolate, capture logs/images, and plan rebuild from known-clean configs. Coordinate with Fortinet proactive customer outreach if you are contacted.
Evidence status
Primary source: FBI/USSS CSA 261006 (2026-10-06). Supporting: Fortinet PSIRT analysis, CISA alert from June 2026, and media reporting (CyberScoop and others).
Forensically, FortiBleed differs from classic “patch a CVE”: attackers do not need a fresh zero-day if valid credentials already circulate in infostealer logs or prior breaches. That makes MFA and unique admin passwords hard requirements, not nice-to-haves. When FBI/USSS state recovery may require steps beyond standard password rotation, update playbooks for “locked out of our firewall” — including physical or out-of-band access, offline config backups, and vendor support. Nordic operators with 24/7 NOCs should tabletop who holds break-glass accounts, where offline configs live, and how to verify no new admin accounts appeared after a suspicious login.
CISA’s June hardening guidance remains relevant: migrate off weak hash algorithms, review VPN profiles, and ensure FortiGate logs are centralized before attackers wipe them. Tie FortiBleed indicators to existing ransomware readiness — the same affiliates named in October reporting buy initial access. Document timelines if you contact authorities or a CERT: first lockout signals, which accounts changed, and whether SSL VPN sessions ended abnormally.