The FortiBleed campaign is still running, according to a joint advisory from the FBI and the U.S. Secret Service. The operation targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, and the advisory cites SOCRadar verification of more than 86,644 compromised devices in 194 countries. The agencies warn that some victims have been locked out of their own devices because the attackers either change or delete passwords for original accounts while creating new ones to maintain persistence.

The attackers are continuing to scan exposed Fortinet firewalls using previously obtained credentials, the advisory states. They use credential stuffing and password spraying with earlier Fortinet leak dumps and infostealer logs, and they crack password hashes on a GPU cluster running Hashcat and Hashtopolis. After gaining access, they enumerate Active Directory accounts, look for privileged users, and sell access to affiliates of the INC/Lynx and Payload ransomware groups.

All four sources agree on the core details of the advisory, including the scale of compromise and the lockout risk. The Register notes that tens of thousands more victims have been added and more ransomware groups are involved, while Recorded Future News frames the warning as an update to earlier guidance. The advisory says recovery may require remediation beyond standard patching and password resets, and it urges victims to report incidents and avoid paying ransoms.