The FBI and Secret Service's latest advisory confirms what many security teams already suspected: credential-based attacks on network perimeter devices are rampant. The FortiBleed campaign has compromised more than 86,000 Fortinet FortiGate firewalls and VPN gateways across 194 countries, turning security chokepoints into open doors for ransomware affiliates.
This isn't about a software vulnerability you can patch. It's about credential hygiene, exposure management, and administrative access controls. Attackers used credential stuffing, password spraying, and reused credentials to maintain access, then sold that access to ransomware operators including INC/Lynx and Payload affiliates.
If you're running Fortinet devices (or any internet-facing security appliance), this checklist will help you verify your current posture and close gaps before they become incidents.
Prerequisites
Before starting this checklist, ensure you have:
- Administrative access to all Fortinet FortiGate devices in your environment
- Current device inventory including firmware versions and management interfaces
- Authority to terminate active sessions and force credential resets
- Access to authentication logs covering the past 90 days minimum
- Documented change control process for emergency configuration changes
Credential and Access Validation
1. Audit all administrative accounts on FortiGate devices
Review every account with administrative privileges. Cross-reference against your identity management system and HR records. Look for accounts you don't recognize, generic usernames (admin2, backup_admin), or accounts tied to former employees.
Good looks like: Every account maps to a current employee with documented business justification. No orphaned accounts, no shared credentials, no "just in case" backdoors.
2. Reset all administrative passwords immediately
Don't wait for evidence of compromise. The FBI and Secret Service recommend this step because attackers maintain access through credential reuse. Use your privileged access management system to generate unique, complex passwords for each account.
Good looks like: Passwords meet NIST SP 800-63B guidelines (minimum 12 characters, no complexity requirements that encourage predictable patterns), stored in a password vault, never reused across devices.
3. Terminate all active admin VPN sessions
Force all administrative sessions to disconnect. Review the list of terminated sessions for unexpected IP addresses, unusual connection times, or sessions from geographic locations where your team doesn't operate.
Good looks like: Zero active sessions after termination. All reconnections come from expected IP ranges within your defined maintenance windows.
4. Enable multi-factor authentication on all administrative interfaces
If you haven't already, configure MFA for every account that can modify firewall rules, VPN configurations, or user permissions. Hardware tokens or authenticator apps are preferable to SMS-based codes.
Good looks like: 100% MFA coverage for administrative access. No exceptions, no "break glass" accounts without MFA, no SMS fallbacks.
Exposure and Configuration Hardening
5. Remove internet-facing management interfaces
The FBI and Secret Service recommend restricting external management or removing internet administration altogether. If you must manage devices remotely, do it through a jump box on a dedicated management network, not directly from the internet.
Good looks like: Management interfaces listen only on internal network segments. External access requires VPN connection to management VLAN, logged and monitored separately from production traffic.
6. Implement IP allowlisting for administrative access
Configure your devices to accept administrative connections only from specific IP addresses or ranges. This won't stop a determined attacker who's already inside your network, but it blocks the mass scanning operations that FortiBleed operators used to identify targets.
Good looks like: Allowlist includes only your known management workstations and jump boxes. List is reviewed quarterly and updated within 24 hours of infrastructure changes.
7. Disable unused VPN portals and protocols
If you're not actively using SSL VPN functionality, disable it. The FortiBleed campaign specifically targeted SSL VPN portals because they're internet-facing by design. Review your VPN configurations and shut down anything you don't need.
Good looks like: Only required VPN protocols are enabled. Unused features are disabled at the configuration level, not just left inactive.
Monitoring and Detection
8. Review authentication logs for the past 90 days
Look for patterns that indicate credential stuffing or password spraying: multiple failed attempts from single IPs, successful logins from unexpected geographic locations, or authentication attempts outside normal business hours. The attackers in this campaign used automated scripts at scale.
Good looks like: You can produce a report showing all authentication attempts, success rates by account, and source IPs. Anomalies are flagged for investigation, not just logged and forgotten.
9. Configure alerts for new administrative account creation
The FortiBleed operators created new accounts to maintain persistence. Your SIEM or logging system should alert immediately when any account with administrative privileges is added.
Good looks like: Real-time alerts to your security operations team. Alert includes account details, creating user, and timestamp. Requires acknowledgment within 15 minutes.
10. Enable session recording for administrative access
You need visibility into what administrators actually do during their sessions. This isn't about distrust; it's about forensics. If an attacker uses stolen credentials, session recordings show you exactly what they accessed.
Good looks like: All administrative sessions are recorded with keystroke logging and screen capture. Recordings are stored in tamper-evident storage for minimum 90 days.
Ongoing Validation
11. Implement quarterly access reviews
Don't let this checklist be a one-time exercise. Schedule recurring reviews of administrative accounts, VPN configurations, and access logs. The FortiBleed campaign has persisted for months because organizations don't maintain continuous verification.
Good looks like: Calendar-scheduled reviews with defined owners. Each review produces a sign-off document listing accounts reviewed, changes made, and exceptions documented.
12. Test your incident response plan for credential compromise
Run a tabletop exercise specifically focused on this scenario: an attacker has valid credentials to your perimeter devices. Who gets notified? How quickly can you lock them out? What's your communication plan?
Good looks like: Written runbook with specific steps, contact information, and decision trees. Exercise completed within past six months with lessons learned documented.
Common Mistakes
Waiting for evidence of compromise before acting. The FBI and Secret Service issued this advisory because the campaign is ongoing. Reset credentials now, not after you find suspicious logs.
Assuming MFA makes you immune. MFA is critical, but the FortiBleed operators demonstrated they can work around weak implementations. Use phishing-resistant methods like hardware tokens or certificate-based authentication.
Treating this as a Fortinet-specific problem. The techniques used in FortiBleed work against any internet-facing device with weak credential hygiene. Apply these controls to your entire perimeter infrastructure.
Failing to document your baseline. You can't detect anomalies if you don't know what normal looks like. Document your current state before making changes so you can measure improvement and spot deviations.
Next Steps
Complete items 1-4 within 48 hours. These are your immediate risk reduction measures. Items 5-10 should be finished within two weeks. Items 11-12 are your ongoing operational controls.
After you've worked through this checklist, review your broader Privileged Access Management strategy. The FortiBleed campaign succeeded because organizations treated network devices as set-and-forget infrastructure rather than high-value targets requiring the same controls as domain controllers or financial systems.
Your perimeter devices are the keys to your kingdom. Treat their credentials accordingly.




