Jessica Entwistle
October 7 2026
The FBI and US Secret Service have issued a renewed warning that the FortiBleed campaign, first disclosed this summer, remains an active threat to organisations using Fortinet VPN appliances. CyberScoop reports that attackers are exploiting known vulnerabilities in unpatched Fortinet devices to gain initial access, then using that foothold to lock out legitimate users or deploy ransomware. The agencies warn that organisations relying on Fortinet VPNs for remote access should assume they are being actively targeted and should prioritise patching, credential rotation and monitoring for signs of compromise. The campaign has been linked to multiple ransomware incidents affecting organisations in healthcare, manufacturing and other sectors. The fact that this campaign has been active for months and continues to succeed suggests many organisations have not yet patched known vulnerabilities or implemented sufficient monitoring to detect exploitation attempts.
This warning is particularly relevant for UK organisations because Fortinet VPN appliances are widely deployed across enterprises, managed service providers and critical infrastructure sectors. The FortiBleed campaign demonstrates how attackers are systematically targeting remote access infrastructure, knowing that VPN appliances often sit at the perimeter and provide a direct route into internal networks. Once compromised, these devices can be used to harvest credentials, move laterally, disable security controls or deploy ransomware. VPN appliances are attractive targets because they are always on, internet-facing, and often have privileged access to internal networks. The fact that attackers are using these compromised devices to lock out legitimate users suggests they are attempting to prevent incident response teams from accessing systems to investigate or remediate the breach. For UK organisations, this highlights the importance of treating remote access infrastructure as critical security assets that require rigorous patch management, monitoring and access controls.
UK businesses using Fortinet VPN appliances should verify that all devices are running the latest firmware and that all known vulnerabilities have been patched. Review whether multi-factor authentication is enforced for all remote access, including administrative access to the VPN appliance itself. Ensure logging and monitoring are configured to detect unusual authentication attempts, configuration changes, firmware updates or unusual traffic patterns. Consider whether your organisation has a process for responding to vendor security advisories affecting perimeter devices and whether incident response plans include procedures for isolating compromised VPN infrastructure quickly. Review whether administrative access to VPN appliances is restricted to specific IP addresses or management networks, and whether default credentials have been changed. Consider whether your organisation has tested its ability to maintain remote access if the primary VPN infrastructure is compromised or taken offline, and whether alternative access methods are documented and tested. Finally, review whether credential rotation policies are in place for VPN accounts, particularly for service accounts or shared credentials that may have been exposed in previous breaches.
Source: CyberScoop