Back to Blog
Fortinet FortiGate Ransomware: Global Credential Harvesting Locks Out 86,000 Devices (June 2024)
ransomware

Fortinet FortiGate Ransomware: Global Credential Harvesting Locks Out 86,000 Devices (June 2024)

breachwire TeamOct 8, 20265 min read

Fortinet: What Happened

A coordinated ransomware campaign, identified as FortiBleed, has compromised more than 86,000 Fortinet FortiGate firewalls across 194 countries. Threat actors executed credential harvesting and brute-force attacks to obtain administrative access, subsequently locking legitimate customers out of their firewall and VPN devices. The campaign has been attributed to ransomware groups including INC, Lynx, and Payload, who are leveraging these compromised devices as initial access points for further ransomware operations. The scope of the attack is global, affecting critical infrastructure sectors and organizations reliant on FortiGate appliances for network security.

Attack Vector & Technical Detail

Attackers exploited weak or reused credentials, employing brute-force and credential harvesting techniques to gain unauthorized access to FortiGate firewalls. Once inside, they established persistent backdoors, ensuring continued administrative control even if passwords were changed. The campaign aligns with MITRE ATT&CK tactics TA0001 (Initial Access), TA0005 (Defense Evasion), TA0006 (Credential Access), and TA0007 (Discovery). Although no specific CVEs or IOCs were provided in the current dataset, the attack methodology indicates a focus on credential-based exploitation rather than exploitation of known software vulnerabilities. The persistent access facilitated lateral movement and enabled ransomware deployment at scale.

Confirmed Impact

The FortiBleed campaign has resulted in legitimate customers being locked out of their FortiGate firewall and VPN devices, with attackers maintaining persistent administrative access. The impact spans 194 countries, affecting organizations in critical infrastructure sectors globally. The compromise of these devices not only disrupts operational continuity but also exposes affected organizations to secondary ransomware attacks, data loss, and potential regulatory scrutiny due to the scale and nature of the breach. The involvement of multiple ransomware groups increases the risk of data exfiltration and extortion attempts.

What This Means for Your Organization

Organizations using Fortinet FortiGate appliances should recognize the elevated risk posed by credential-based attacks, especially in environments lacking multi-factor authentication or robust password policies. The campaign demonstrates that attackers are actively targeting network edge devices as high-value entry points for ransomware operations. Immediate review of access controls, credential hygiene, and device monitoring is critical. Proactive defensive measures, such as enforcing strong authentication and monitoring for anomalous administrative activity, are essential to mitigate the risk of similar compromises.

Detection & Response

  • Immediate: Audit all FortiGate firewall and VPN device accounts for unauthorized changes and enforce password resets for all administrative users.
  • Hunt: Monitor for anomalous login attempts, brute-force activity, and persistence mechanisms on FortiGate devices, particularly administrative account creation or modification.
  • Patch: N/A (no CVE specified; focus on credential management and device hardening).

Source: https://www.cybersecuritydive.com/news/fbi-fortibleed-credential-harvesting-attacks/832366/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: