The FortiBleed attack has not been stemmed, with the FBI and U.S. Secret Service (USSS) issuing a joint warning on the continuing risk to Fortinet firewalls.
The agencies warned that more than 86,644 devices across 194 countries have been compromised to date and that bad actors are continuing to scan exposed Fortinet devices using previously stolen credentials, placing a considerable threat of firewall lockout.
“Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the advisory warned, though it did not disclose how many organizations have so far experienced lockouts.
It also spotlighted the FortiBleed attack chain as an initial entry point for ransomware affiliates.
Organizations were advised to investigate indicators of compromise including 13 IP addresses observed conducting brute-force attacks. The document also identified almost 20 account names found following intrusions, including fortiAdmin, forticloud-sync, adminsslvpn, forticloud-tech, and support_fortinet.
As exposed in June, the credential-harvesting campaign embroiled the likes of Oracle, Comcast, and Samsung, leading to the leak of thousands of enterprise-level sign-in details.
FortiBleed was achieved through the use of a 45-GPU cluster to process stolen password data. Attackers used this computing power to analyze credential patterns each time the cluster successfully cracked one password, helping to generate variants for other accounts at scale.
The FBI and USSS advised that organizations restrict external management access to trusted hosts, implement local-in policies, or ideally disable internet-based administration altogether. They also recommended terminating active administrator and VPN sessions, resetting Fortinet credentials, and enforcing strong passwords alongside phishing-resistant multifactor authentication.
Organizations should also check firewall and VPN configurations for unauthorized changes, and store administrator credentials using the stronger password-based key derivation function one and two (PBKDF2) hashing algorithm rather than legacy methods.
Comments