FBI Warns FortiBleed Attacks Still Locking Out FortiGate VPN Admins
The FBI has issued a warning that so-called "FortiBleed" attacks remain active, targeting internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways. According to the report, attackers are not just gaining unauthorized access but are locking legitimate administrators out of their own devices, suggesting a deliberate effort to maintain persistence and deny recovery.
Why It Matters
FortiGate appliances are widely deployed as perimeter firewalls and VPN gateways, making them a high-value target for initial access. An admin lockout scenario is particularly disruptive: it can delay incident response, block emergency patching, and leave organizations unable to revoke attacker access through normal management channels while the compromise is ongoing. Any organization running internet-facing FortiGate SSL VPN or management interfaces should treat this as a current, active threat rather than a historical incident.
What Defenders Should Watch For
- Unexpected administrator account lockouts, password/credential changes, or failed admin logins on FortiGate devices
- New or modified local admin accounts, API tokens, or certificate-based auth configured without change-management approval
- Unusual SSL VPN session activity from unfamiliar source IPs, especially sessions established outside normal business patterns
- Changes to firewall/VPN configuration, routing, or logging settings that could suggest an attacker covering tracks
- Loss of management-plane access (web admin UI, SSH, or API) that cannot be explained by legitimate IT activity
At a high level, organizations should review exposure of FortiGate management and VPN interfaces to the internet, ensure out-of-band access to recover from lockouts, confirm devices are on current firmware, and monitor authentication and configuration-change logs closely until more technical detail becomes available.
Developing Situation
Details on the specific exploitation method, affected firmware versions, and indicators of compromise have not yet been fully disclosed at the time of this writing. This is a developing story based on an FBI advisory; defenders should treat current information as preliminary and monitor for updates. Read the original report at BleepingComputer.