# FBI and Secret Service warn FortiBleed enables lockouts and ransomware

_Published Tuesday, October 6, 2026 at 6:18 PM EDT · Security · Latest · Tier 2 — Notable_

![FBI and Secret Service warn FortiBleed enables lockouts and ransomware — Primary](https://cyberscoop.com/wp-content/uploads/sites/3/2024/10/GettyImages-1670649574.jpg)

The FBI and Secret Service warned Tuesday that the ongoing FortiBleed credential compromise campaign can lock organizations out of Fortinet firewalls and VPN gateways and provide initial access for ransomware attacks, CyberScoop reported.

Attackers use stolen credentials to access exposed devices, create administrator accounts and change passwords or disable accounts. Initial access brokers are supplying access to ransomware affiliates including INC/Lynx and Payload.

The agencies recommend restricting or removing internet administration, resetting credentials, enabling multifactor authentication and checking users and logs for unauthorized activity. Account changes can require remediation beyond standard patching and password resets.

## Sources

- [CyberScoop](https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/)

---
Canonical: https://techandbusiness.org/newswire/ONhyBwCabyw_mKvjlt60E5
Published: 2026-10-06T22:18:51.744Z
Story chronology: 2026-10-06T21:03:58.000Z
Retrieved: 2026-10-07T00:05:40.662Z
Publisher: Tech & Business (techandbusiness.org)
