Threat advisory · Multiple

FBI says FortiBleed attacks on Fortinet firewalls are still active

On Oct 6, 2026 the FBI warned FortiBleed is still hitting Fortinet firewalls and VPNs. Check accounts, reset passwords and turn on MFA now.

On October 6, 2026, the U.S. Federal Bureau of Investigation (FBI) and Secret Service warned that FortiBleed, a campaign that uses stolen passwords to break into Fortinet firewalls and virtual private networks (VPNs), is still active and locking some owners out. If your organization uses a FortiGate, review its accounts, reset passwords and turn on multi-factor authentication today.

What happened

On Tuesday, October 6, 2026, the FBI and the U.S. Secret Service published a joint advisory titled “FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts.” The advisory says attackers “are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials.”

FortiBleed is not new. Security firms SOCRadar and Hudson Rock first documented it in June 2026, The Hacker News reported, and the Canadian Centre for Cyber Security issued its own alert (AL26-014) on June 18, 2026. What the new advisory adds is that the campaign hasn’t stopped, and that it is causing lockouts.

According to the advisory, attackers:

  • scan the internet for exposed FortiGate SSL VPN login pages
  • try passwords from earlier leaks and from “infostealer” malware logs
  • crack stolen password data offline, helped by weaker legacy password storage on some devices
  • create new administrator accounts to keep access, and sometimes delete or change the real owner’s accounts
  • move into the wider network, then sell that access to ransomware groups, currently including INC/Lynx and Payload

The advisory cites SOCRadar’s count of more than 86,644 compromised devices across 194 countries. Cybersecurity Dive reported that SOCRadar also says more than 430,000 FortiGate firewalls have been targeted. Neither source gives a figure for Canada, and it is not yet known how many Canadian organizations are affected.

Who is affected

Any organization with a Fortinet FortiGate firewall or SSL VPN gateway that can be reached from the internet. The risk is highest where:

  • admin or VPN accounts use passwords that have been reused elsewhere or appeared in an earlier leak
  • multi-factor authentication isn’t turned on for VPN and admin logins
  • the firewall’s management page is open to the whole internet

If you use Fortinet equipment, this is worth checking even if you have seen no sign of trouble.

What to do now

If you run a Fortinet firewall or VPN

These steps come from the FBI and Secret Service advisory and the Cyber Centre’s June alert.

  1. List every account on the device. Remove or disable any you don’t recognize. Watch for names the advisory flags, including forticloud-sync, forticloud-tech, fortiAdmin, adminsslvpn, support_fortinet and itadmin.
  2. End all active admin and VPN sessions, then reset every Fortinet VPN and administrator password.
  3. Turn on multi-factor authentication (MFA) for all remote access and admin accounts. The advisory recommends phishing-resistant MFA, for example a hardware security key.
  4. Close the management page to the internet. Allow admin access only from trusted addresses, or remove internet-based administration entirely.
  5. Compare the configuration against a known-good backup and check for unexpected changes, including unknown REST API keys (keys that let other software control the device).
  6. Review logs from the firewall, VPN and domain controllers for unusual logins or new accounts.
  7. Update the firmware and switch admin password storage to the stronger PBKDF2 method that Fortinet supports from FortiOS 7.2.11 onward.

If you find signs of compromise, the advisory recommends isolating the device and keeping its logs before making changes. In Canada, you can report the incident to the Cyber Centre through My Cyber Portal or at [email protected].

If you work somewhere that uses a Fortinet VPN

Don’t reuse your VPN password anywhere else, and accept MFA when your IT team turns it on. If you’re asked to reset your password this week, that’s likely why.

What this means for organizations in BC and Alberta

A compromised firewall is a security incident, but it only becomes a reportable privacy breach if personal information was accessed or exposed. That is why the log review above matters: it tells you which side of the line you’re on.

If personal information was involved:

  • Organizations covered by PIPEDA (the Personal Information Protection and Electronic Documents Act, Canada’s federal private-sector privacy law): you must report to the Office of the Privacy Commissioner of Canada and notify affected people as soon as feasible when the breach creates a real risk of significant harm.
  • Alberta private organizations (Alberta PIPA, the Personal Information Protection Act): the same “real risk of significant harm” test applies. You must notify Alberta’s Office of the Information and Privacy Commissioner and affected individuals without unreasonable delay.
  • BC private organizations (BC PIPA): there is currently no mandatory breach notification requirement, but BC’s Office of the Information and Privacy Commissioner recommends notifying voluntarily.

Organizations in British Columbia and Alberta that handle health, financial or client records should also check any sector rules and cyber insurance terms that apply to them.

How happier IT helps

If you’d like a second pair of eyes, we can check your FortiGate’s accounts, access settings and MFA as part of firewall management, and keep watching it afterwards through our managed security services. Not sure where you stand? Our free IT assessment is a calm, no-pressure place to start.

Sources

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.