FBI warns FortiBleed campaign remains active
The FBI and U.S. Secret Service warned that FortiBleed remains active, targeting internet-facing Fortinet FortiGate firewalls and VPN gateways through reused or leaked credentials rather than a newly identified software flaw. The agencies said the campaign can let attackers take over accounts, create new administrator accounts and, in some cases, lock organizations out of their devices. A June 19, 2026, snapshot from cybersecurity firm SOCRadar counted 86,644 compromised devices across 194 countries. That figure is a dated estimate, not a confirmed count of all affected organizations or a measure of every device targeted. A separate tally of 320,777 FortiGate targets and an earlier estimate of about 74,000 devices with credential exposure describe different measures and should not be treated as directly comparable totals. According to the federal advisory, attackers scan for exposed FortiGate SSL VPN portals and use credential stuffing and password spraying with previously leaked or stolen login data. The campaign also exploits legacy SHA256 password storage, which can make stolen authentication data easier to crack.