The FBI and US Secret Service are warning organizations that the FortiBleed campaign targeting Fortinet devices remains active, months after thousands of exposed credentials first appeared online.
FortiBleed targets internet-accessible Fortinet firewalls and VPN gateways using compromised credentials. Rather than exploiting a newly discovered security flaw, attackers are attempting to gain access with passwords obtained from previous incidents and through techniques such as brute-force and credential-stuffing attacks.
The campaign attracted widespread attention in June after credentials associated with tens of thousands of Fortinet devices were exposed. Security researchers subsequently found signs that the broader operation had targeted a significantly larger number of systems around the world.
The latest government warning shows that the threat did not end with the original credential leak. Attackers are continuing to use stolen login details to access exposed devices, where they can make unauthorized changes and potentially move deeper into company networks.
In some incidents, attackers have changed passwords or disabled legitimate accounts after gaining access. This can leave administrators locked out of their own Fortinet systems and make recovery more complicated than simply installing updates or resetting one password.
The FBI also warns that compromised Fortinet devices are being used as an entry point for ransomware attacks. Access obtained through FortiBleed has been observed being passed to ransomware affiliates, including operations associated with INC/Lynx and Payload.
Fortinet has stressed that FortiBleed does not represent a new vulnerability in its products. The company believes the activity involves credentials connected to previous security incidents combined with attacks against systems protected by weak passwords or lacking multi-factor authentication.
Organizations using Fortinet equipment are being urged to limit or completely remove internet-facing administrative access, reset potentially exposed credentials, and enable multi-factor authentication. Administrators should also check for unknown accounts, password changes, and other suspicious modifications.
Simply changing passwords may not be enough if attackers have already gained access. Organizations should review their devices and network activity for signs of unauthorized changes or movement into other systems, particularly because the FBI says FortiBleed continues to provide criminals with a path toward more damaging ransomware attacks.