# FBI and Secret Service Warn of FortiBleed Attacks

The FBI and U.S. Secret Service warn that the FortiBleed campaign remains active against Fortinet firewalls and VPN gateways, with reports of more than 80,000 devices affected worldwide. Attackers may use compromised credentials to create, alter, or delete administrator accounts, lock legitimate users out of firewalls, and potentially enable ransomware access. For federal contractors and other organizations that rely on these systems, the activity presents an operational-continuity and cybersecurity risk that may affect secure service delivery and contract performance.

- Contractors using FortiGate devices should review FBI indicators and firewall and identity logs, remove unauthorized access, and reset affected credentials.
- The agencies recommend restricting or disabling internet-facing administration, enforcing multifactor authentication—including phishing-resistant MFA—and securely storing credentials.
- Procurement and security teams can use the alert to assess exposure in their own environments and coordinate remediation with relevant IT and cybersecurity service providers.

**Jurisdictions:** federal
**Industries:** Information Technology, Public Safety
**Topics:** Cybersecurity, Digital Infrastructure
**Published:** October 08, 2026

### Government Entities
- Federal Bureau of Investigation (FBI)
- United States Secret Service (USSS)

### Key Quotes
> What stands out for me is that FortiBleed is still an active threat, and attackers are using stolen credentials to access the exposed Fortinet devices, create new administration accounts, and in some cases, lock the real owners out.
> — Ensar Seker, Chief Information Security Officer

> When you no longer have access to your own firewall, you cannot just apply a software patch and move on.
> — Ben Bernstein, Manager, Cybersecurity Advisors Team

### Sources
- [Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks | CyberScoop](https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning) - CyberScoop
- [FBI: FortiBleed attackers can lock organizations out of their own firewalls | CSO Online](https://www.csoonline.com/article/4232481/fbi-fortibleed-attackers-can-lock-organizations-out-of-their-own-firewalls.html) - CSO Online