Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks | #ransomware | #cybercrime

FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday.
“Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the alert states. “In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.”
When it was first uncovered earlier this year, SOCRadar verified more than 86,644 compromised devices across 194 countries. Ensar Seker, chief information security officer of the company, told CyberScoop that “in our later investigation, we identified more than 400,000 or 450,000 firewalls targeted by the wider operation.”
There are different aspects of the operation that make comparisons imprecise over time, but overall the numbers “show the campaign is broader and more serious than we understood at the beginning,” Seker said.
The attackers can disable accounts or change passwords to lock users out with the access they gain, making standard password resets and patching insufficient, the government alert reads.
The alert also warns that initial access brokers are making use of the FortiBleed attack to provide access to ransomware affiliates, including INC/Lynx and Payload.
The government warning provides additional confirmation about the most worrisome elements of FortiBleed, Seker said.
“What stands out for me is that FortiBleed is still an active threat, and attackers are using stolen credentials to access the exposed Fortinet devices, create new administration accounts, and in some cases, lock the real owners out,” he said. “The FBI and the Secret Service also confirm that the success can lead to ransomware attacks as well.”
The FBI and Secret Service recommend that Fortinet customers restrict external management or remove internet administration entirely, reset credentials, set up multifactor authentication, review firewall and VPN users for unauthorized changes, review logs for potential lateral movement, and enable secure credential storage.
The agencies are seeking any information and indicators of compromise that organizations can share, including IP addresses and any usernames the attackers use.


