FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
Tens of thousands more victims and more ransomware groups getting in on the act
The FBI and US Secret Service have confirmed that criminals are still exploiting the FortiBleed campaign to attack Fortinet firewalls and SSL VPN gateways. The agencies reported on Tuesday that over 86,644 compromised devices have been identified across 194 countries. Victims may be locked out of their Fortinet devices if threat actors delete or change original account passwords.
During initial intrusions, attackers create new accounts while deleting existing ones to block access and maintain persistence. Threat actors use credentials from previous breaches and steal password hashes from compromised devices. Experts advise organizations to restrict internet-facing management access, terminate VPN sessions, reset passwords, and enable phishing-resistant multi-factor authentication.
The FBI and Secret Service linked FortiBleed to ransomware campaigns, noting that initial access brokers provided compromised-network access to ransomware affiliates. At least 12 ransomware attacks linked to FortiBleed have been confirmed so far, primarily by affiliates associated with the INC/Lynx and Payload ransomware groups.
The agencies urged victims to report incidents without the obligation to share information, warning against ransom payments.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.