FBI and Secret Service warn FortiBleed attackers are locking administrators out of Fortinet firewalls
The credential campaign, which SOCRadar says has compromised 86,644 devices in 194 countries, is serving as an entry point for ransomware affiliates.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
The FBI and the US Secret Service have released a joint advisory warning that the FortiBleed campaign against internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways is still active. The attackers are now changing passwords and deleting accounts so that legitimate administrators can no longer get in. BleepingComputer reports that the attackers gain access with previously leaked credentials, infostealer logs, credential stuffing and password spraying. They then pull more authentication data from compromised devices and crack the stolen password hashes offline on a distributed GPU cluster running Hashcat and Hashtopolis. The FBI says the attack chain has been an initial entry point for ransomware affiliates, including INC/Lynx and Payload. FortiBleed came to light in June, when attackers accidentally exposed a server holding usernames and plaintext passwords tied to 73,932 firewall URLs. SOCRadar now counts about 86,644 confirmed compromised devices in 194 countries. It stresses that this is a count of confirmed breaches, not an estimate of exposure, and that devices breached months ago remain in the attackers' inventory. SecurityWeek notes that a Russian initial access broker has been blamed for the campaign. Organizations running exposed Fortinet appliances face the risk of losing control of their perimeter devices even if they were breached long ago, so the warning matters well beyond the period of the original leak.