This article is intended to give you the high-level, non-technical information you need to check your organisation’s exposure and respond. If your organisation does not use Fortinet products, you can stop reading here. If it does, keep reading.
What is Fortibleed?
Fortibleed is not a vulnerability within the Fortinet products below, so patching does not completely mitigate the risks. Fortibleed is a credential harvesting campaign run by the threat actor Lynx/ INC targeting these products:
- Fortinet FortiGate firewalls
- Fortinet SSL VPN gateways
- FortiWeb
- MSSQL services (this is not a Fortinet product but has also been targeted as part of this campaign)
What does it do?
The campaign has two parts:
- It used valid credentials from previous Fortinet breaches and infostealer logs to access Internet-exposed Fortinet firewalls and VPN gateways;
- Once access is verified, it deploys a tool that monitors traffic and captures cleartext and hashed credentials (usernames and passwords) from traffic passing through the compromised device or service. The threat actors then use those credentials to gain access to Active Directory and other available services.
What do you need to do?
Security patches alone do not fully mitigate this campaign. While you should ensure you are running the latest versions of your Fortinet services, other actions are required:
- Check your exposure – SOCRadar released a free checker here https://socradar.io/free-tools/fortibleed
- Rotate credentials for Fortinet products
- Thoroughly review your Fortinet product’s configuration, accounts, and settings as threat actors may have tampered with them to maintain their access
- Assess wider impact – if your Fortinet product is confirmed compromised, assume credentials that passed through the service are impacted and change them immediately
Fortinet recommends the following:
To defend against this malicious cyber activity, Fortinet recommends that customers with impacted FortiGate appliances to immediately:
- Terminate all admin and VPN sessions and reset credentials. Terminate all active administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.
- Implement MFA on all administrator and VPN user accounts.
- Upgrade to latest versions of 7.4, 7.6, or 8.0. These versions support ****PBKDF2 hashing of administrator credentials. Follow the guidance to remove older legacy password settings via set login-lockout-upon-weaker-encryption.
- Validate configuration. Review firewall and VPN users and other configuration for unauthorized changes. Preferably compare to a known good configuration. Pay particular attention to the addition of unrecognized accounts, such as “forticloud, fortiuser, fortinet-support, fortinet-tech-support,” etc.
- Check your logs. Look for unexpected administrator access from an unknown IP and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes.
- Reduce your attack surface and lock down management access. Restrict external management of your devices via trusted hosts (good), a local-in policy (better), or remove internet administration altogether (best).
Additional security best practices for administrator access and general hardening can be found in the Best Practices Guides.
If there is any evidence of unapproved modification of the configuration or other IoCs:
- Treat the devices as compromised and follow the guidance here to recover.
- Check for the creation of VPN users, unexpected password resets, or VPN from unexpected locations, which may indicate the actor has attempted lateral movement into the internal network.
- If AD/LDAP integration is configured, it is important to treat this account as compromised and monitor your AD for its use for authentication elsewhere or the creation of additional accounts and monitor your network for lateral movement.
For more in-depth analysis, refer to the following reports:




