The FBI and U.S. Secret Service say the ongoing FortiBleed campaign is still active, targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. In addition to stealing credentials, attackers can disrupt access by deleting or changing passwords, which may lock administrators out of affected devices.

The agencies cite external tracking that has identified a large number of compromised Fortinet systems across many countries. Reporting also highlights potential downstream impacts, including possible ransomware activity, depending on what an intrusion enables after initial compromise. Coverage across outlets largely aligns on the campaign’s persistence and the specific Fortinet product types involved, while emphasizing different implications—credential theft, account lockout, and the risk of further attacks—rather than changes in the underlying threat technique.