FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
Tens of thousands more victims and more ransomware groups getting in on the act
The FBI and US Secret Service have confirmed that criminals are still attacking organizations using Fortinet firewalls in a campaign known as FortiBleed. These criminals exploit credentials obtained from earlier breaches and infostealer logs, using credential stuffing and password spraying techniques to gain unauthorized access.
They then crack password hashes offline using powerful GPU clusters. According to a joint advisory published on Tuesday, over 86,644 devices across 194 countries have been compromised. Victims may be locked out of their Fortinet devices if threat actors delete or alter their original accounts. In some cases, threat actors create new accounts or delete existing ones to block organizations from accessing affected devices and maintain persistence in the system.
The FBI and Secret Service have urged organizations to restrict internet-facing management access, terminate active sessions, reset passwords, and enable phishing-resistant multi-factor authentication. They also mentioned a potential link between FortiBleed and ransomware campaigns, noting that initial access brokers have supplied compromised-network access to ransomware affiliates.
At least 12 ransomware attacks have been confirmed so far, allegedly carried out by affiliates associated with the INC/Lynx and Payload ransomware groups. The FBI and Secret Service encouraged victims to report incidents without requiring them to disclose information, cautioning against paying ransoms.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.