Threat advisory · Multiple
FBI says FortiBleed attacks on Fortinet firewalls are still active
On Oct 6, 2026 the FBI warned FortiBleed is still hitting Fortinet firewalls and VPNs. Check accounts, reset passwords and turn on MFA now.
On October 6, 2026, the U.S. Federal Bureau of Investigation (FBI) and Secret Service warned that FortiBleed, a campaign that uses stolen passwords to break into Fortinet firewalls and virtual private networks (VPNs), is still active and locking some owners out. If your organization uses a FortiGate, review its accounts, reset passwords and turn on multi-factor authentication today.
What happened
On Tuesday, October 6, 2026, the FBI and the U.S. Secret Service published a joint advisory titled “FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts.” The advisory says attackers “are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials.”
FortiBleed is not new. Security firms SOCRadar and Hudson Rock first documented it in June 2026, The Hacker News reported, and the Canadian Centre for Cyber Security issued its own alert (AL26-014) on June 18, 2026. What the new advisory adds is that the campaign hasn’t stopped, and that it is causing lockouts.
According to the advisory, attackers:
- scan the internet for exposed FortiGate SSL VPN login pages
- try passwords from earlier leaks and from “infostealer” malware logs
- crack stolen password data offline, helped by weaker legacy password storage on some devices
- create new administrator accounts to keep access, and sometimes delete or change the real owner’s accounts
- move into the wider network, then sell that access to ransomware groups, currently including INC/Lynx and Payload
The advisory cites SOCRadar’s count of more than 86,644 compromised devices across 194 countries. Cybersecurity Dive reported that SOCRadar also says more than 430,000 FortiGate firewalls have been targeted. Neither source gives a figure for Canada, and it is not yet known how many Canadian organizations are affected.
Who is affected
Any organization with a Fortinet FortiGate firewall or SSL VPN gateway that can be reached from the internet. The risk is highest where:
- admin or VPN accounts use passwords that have been reused elsewhere or appeared in an earlier leak
- multi-factor authentication isn’t turned on for VPN and admin logins
- the firewall’s management page is open to the whole internet
If you use Fortinet equipment, this is worth checking even if you have seen no sign of trouble.
What to do now
If you run a Fortinet firewall or VPN
These steps come from the FBI and Secret Service advisory and the Cyber Centre’s June alert.
- List every account on the device. Remove or disable any you don’t recognize. Watch for names the advisory flags, including
forticloud-sync,forticloud-tech,fortiAdmin,adminsslvpn,support_fortinetanditadmin. - End all active admin and VPN sessions, then reset every Fortinet VPN and administrator password.
- Turn on multi-factor authentication (MFA) for all remote access and admin accounts. The advisory recommends phishing-resistant MFA, for example a hardware security key.
- Close the management page to the internet. Allow admin access only from trusted addresses, or remove internet-based administration entirely.
- Compare the configuration against a known-good backup and check for unexpected changes, including unknown REST API keys (keys that let other software control the device).
- Review logs from the firewall, VPN and domain controllers for unusual logins or new accounts.
- Update the firmware and switch admin password storage to the stronger PBKDF2 method that Fortinet supports from FortiOS 7.2.11 onward.
If you find signs of compromise, the advisory recommends isolating the device and keeping its logs before making changes. In Canada, you can report the incident to the Cyber Centre through My Cyber Portal or at [email protected].
If you work somewhere that uses a Fortinet VPN
Don’t reuse your VPN password anywhere else, and accept MFA when your IT team turns it on. If you’re asked to reset your password this week, that’s likely why.
What this means for organizations in BC and Alberta
A compromised firewall is a security incident, but it only becomes a reportable privacy breach if personal information was accessed or exposed. That is why the log review above matters: it tells you which side of the line you’re on.
If personal information was involved:
- Organizations covered by PIPEDA (the Personal Information Protection and Electronic Documents Act, Canada’s federal private-sector privacy law): you must report to the Office of the Privacy Commissioner of Canada and notify affected people as soon as feasible when the breach creates a real risk of significant harm.
- Alberta private organizations (Alberta PIPA, the Personal Information Protection Act): the same “real risk of significant harm” test applies. You must notify Alberta’s Office of the Information and Privacy Commissioner and affected individuals without unreasonable delay.
- BC private organizations (BC PIPA): there is currently no mandatory breach notification requirement, but BC’s Office of the Information and Privacy Commissioner recommends notifying voluntarily.
Organizations in British Columbia and Alberta that handle health, financial or client records should also check any sector rules and cyber insurance terms that apply to them.
How happier IT helps
If you’d like a second pair of eyes, we can check your FortiGate’s accounts, access settings and MFA as part of firewall management, and keep watching it afterwards through our managed security services. Not sure where you stand? Our free IT assessment is a calm, no-pressure place to start.
Sources
- FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts, FBI and U.S. Secret Service, October 6, 2026
- AL26-014: FortiBleed leak of thousands of compromised credentials impacting Fortinet devices, Canadian Centre for Cyber Security, June 18, 2026
- FBI, Secret Service add to warnings of FortiBleed credential stealing campaign, The Record, October 7, 2026
- FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users, Cybersecurity Dive, October 7, 2026
- FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials, The Hacker News, October 2026
- How to Handle Mandatory Breach Notifications Under Canadian Privacy Law, Burnet, Duckworth & Palmer LLP (BD&P), April 20, 2026