Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-08 · updated: 2026-10-08 · tags: [incident, global, ransomware] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

The FBI and US Secret Service published an IC3 alert on 6 October warning that FortiBleed — a credential-compromise campaign against Fortinet firewalls and VPN gateways — is an ongoing threat that can leave organisations locked out of their own devices, as attackers disable accounts or change passwords, requiring remediation beyond standard patching and resets. The alert confirms the attack chain is being used by initial-access brokers to sell access to ransomware affiliates, including INC/Lynx and Payload. When SOCRadar first verified the campaign it counted more than 86,644 compromised devices across 194 countries; its CISO now says later investigation identified 400,000–450,000 firewalls targeted by the wider operation. Agencies recommend removing or restricting internet-facing management, resetting credentials, enforcing MFA, auditing firewall/VPN users for rogue accounts and reviewing logs for lateral movement, and they are soliciting indicators of compromise from victims. Not known: how many Australian organisations are affected.

Attribute Detail
Sector Global (Macro)
Date 2026-10-08
Source CyberScoop
Reliability Tier 1