A large-scale credential-harvesting campaign has compromised more than 30,000 Fortinet FortiGate firewalls and VPN gateways across 194 countries, according to SOCRadar, which said the attackers amassed a database of 30,791 verified working credentials. Researchers said the operation targeted internet-facing Fortinet management and VPN interfaces using credential stuffing, password spraying, brute-force attempts, and reused passwords from prior leaks, and found no evidence of a Fortinet zero-day or a breach of Fortinet itself.
The attackers allegedly used compromised devices as listening posts to capture additional credentials and feed them into an automated attack chain, broadening access across sectors including telecommunications, government, healthcare, finance, education, energy, and other critical infrastructure. Telecom was reported as the most affected sector, while government entities accounted for 591 entries across 111 domains; India and the United States represented nearly one-third of identified compromises. SOCRadar said the campaign remained active and assessed it as critical, with tooling and victim selection described as consistent with Russian-speaking threat actors and possible motives spanning both financial gain and cyberespionage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
27 events from the most recent confirmed update back to the earliest known activity.
In a July 2 report, SOCRadar said investigators found Citrix target lists within FortiBleed-related infrastructure and that the actors were using an undisclosed Nextcloud zero-day to expand access. The report did not provide technical details for the Nextcloud exploit but described it as part of the group's broader operational expansion beyond Fortinet-derived access.
Security Affairs reported that SOCRadar attributed at least 12 ransomware deployments, affecting hundreds of encrypted endpoints, to access obtained through the FortiBleed credential-harvesting campaign. The report said evidence from exposed operator files and simultaneous access to INC Ransom and Lynx negotiation panels strengthened the link between FortiBleed and ransomware intrusions.
BleepingComputer reported that investigators linked the FortiBleed credential-theft campaign to the INC and Lynx ransomware operations after finding a Windows server in FortiBleed infrastructure with access to both groups' negotiation panels. The report said victim overlap and recovered tooling suggested stolen Fortinet credentials were later used to support ransomware intrusions.
Arctic Wolf reported reverse engineering a recovered FortiBleed component called the CyberStrike Harvester, providing new technical detail on the credential-focused pipeline behind the campaign. The analysis described an operation centered on credential stuffing, password spraying, configuration harvesting, offline cracking, and post-authentication capture processing rather than a malware payload or Fortinet zero-day.
SecurityWeek reported SOCRadar's assessment that the FortiBleed credential-harvesting operation had been active since at least February 2026, earlier than previously reported. The report described the campaign as a multi-vendor operation targeting exposed edge devices including FortiGate, Sophos SSL-VPN, RDWeb, and other services.
On 2026-06-23, Finland’s National Cyber Security Centre said the FortiBleed campaign had also affected Finland, with leaked data tied to around twenty Finnish targets and a small number of attacks observed domestically. The agency said it had contacted identified Finnish targets and advised credential resets, MFA, software updates, configuration and log review, restricted external administration, and reporting incidents to police and the NCSC.
On 2026-06-23, JPCERT/CC warned that leaked Fortinet-related credentials in the FortiBleed incident included Japanese organizations and could still enable unauthorized access to FortiGate devices and downstream internal compromise. The advisory recommended checking for configuration export traces, suspicious administrator access from published IoC IPs, suspicious accounts or configuration changes, rotating credentials, enabling MFA, investigating Active Directory activity, and updating to PBKDF2-capable FortiOS firmware.
On 2026-06-22, CERT-SE published guidance warning that attackers were exploiting leaked Fortinet credentials at scale, with particular concern for FortiGate firewalls and SSL VPN gateways affected by FortiBleed. The advisory urged organizations to enforce MFA, reduce internet-exposed administration, remove unnecessary accounts, monitor login activity, terminate active sessions, change passwords, review logs, and report suspected intrusions.
On 2026-06-22, Gurucul published a technical analysis of the exposed FortiBleed attacker directory and released IP-based indicators of compromise along with a detection query to help identify related network activity. The report said the campaign relied on stolen and cracked credentials rather than exploitation of a software vulnerability.
On 2026-06-22, Security Affairs reported SOCRadar’s detailed breakdown of FortiBleed, describing a five-phase credential-harvesting operation that abused the legitimate FortiOS 'diagnose sniffer packet' command via a Golang tool called FortigateSniffer to capture authentication traffic across 24 protocols. The report said the campaign had targeted more than 430,000 devices, exposed over 110 million credentials across 659 or more harvesting pipelines, and traced infrastructure from one exposed directory to more than 150 servers while the operation remained active.
In its response to the FortiBleed campaign, Fortinet said the reused credentials were linked to earlier exploitation of FortiCloud SSO authentication bypass vulnerabilities CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719, which had already been patched. The company also said the activity mirrored techniques it had warned about in March, including AI-assisted target identification and password spraying.
On 2026-06-19, Fortinet said the reported FortiBleed activity was a credential-harvesting campaign using reused credentials and brute-force attacks, not a new Fortinet vulnerability or recent Fortinet incident. The company said it had identified potentially compromised systems, launched an investigation with relevant government agencies, and was proactively notifying affected customers while urging credential resets, MFA, and hardening.
On 2026-06-19, CloudSEK published a technical analysis of an exposed FortiBleed attacker back-end and said the campaign was a credential-compromise operation rather than a Fortinet zero-day. The firm said widely cited victim totals were overstated, assessing that 918 organizations showed captured internal Kerberos traffic and only 148 represented confirmed compromises with cracked and verified Active Directory credentials.
Recorded Future’s Insikt Group linked FortiBleed-related activity to IP address 85[.]11[.]187[.]8 and reported infrastructure and tooling consistent with credential harvesting, hash cracking, password spraying, Active Directory enumeration, SMB/DFS collection, staged exfiltration, and log clearing. The report also reiterated attribution to a Russian-speaking threat group and urged immediate credential rotation, MFA enforcement, hardening, and investigation for downstream compromise.
On 2026-06-18, GovInfoSecurity reported researcher Volodymyr Diachenko's attribution of the FortiBleed-related operation to a Russian-speaking multi-operator cybercrime group. The report said the group intercepts SSL VPN authentication, cracks harvested hashes with a Hashtopolis-managed GPU cluster, and pivots from compromised Fortinet devices into internal Active Directory environments.
On 2026-06-18, CISA warned that malicious actors were targeting internet-accessible Fortinet devices in government and private sector organizations using compromised credentials associated with FortiBleed. CISA said the exposure involved roughly 74,000 Fortinet devices and urged organizations to terminate active sessions, reset VPN and admin passwords, enforce phishing-resistant MFA, verify PBKDF2 credential storage, review logs, and restrict public internet management access.
On 2026-06-18, the Canadian Centre for Cyber Security issued Alert AL26-014 warning that exposed Fortinet credentials in the FortiBleed campaign could enable remote access to affected devices and connected networks and allow attackers to alter security settings. The agency advised auditing for unauthorized accounts such as "forticloud-sync" and "forticloud-tech," restricting management access, terminating active sessions, resetting passwords, enforcing MFA, updating firmware, and verifying patches for CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719.
On 2026-06-18, the UK National Cyber Security Centre warned that Fortinet firewalls and VPN gateways were being globally targeted and said there were some indications of potential impact in the UK. The agency advised organizations to investigate for compromise, isolate affected devices, collect forensic artefacts before factory reset, enforce MFA, update or remove unsupported systems, and review for persistence and lateral movement.
A June 18 report said the FortiBleed campaign had successfully compromised more than 86,000 internet-exposed Fortinet firewall and VPN gateway devices across 194 countries. The report said the operation continued using password-based access and adversary-in-the-middle interception rather than a Fortinet breach or zero-day.
On 2026-06-17, TechCrunch reported that organizations including Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC were among the alleged victims of the FortiBleed campaign targeting exposed Fortinet firewalls and VPNs. The report attributed the victim list to Hudson Rock and SOCRadar's analysis of the broader credential-harvesting operation.
Researchers reported that the FortiBleed campaign led to confirmed follow-on compromises at organizations in multiple countries, including persistence, lateral movement, and document exfiltration. The reference specifically cites a Turkish NATO defense contractor among the affected organizations.
On 2026-06-17, Kevin Beaumont reported that a recent dataset containing plaintext or crackable administrator credentials for about 75,000 Fortinet firewall devices appeared legitimate, with many affected devices still online and exposing management interfaces to the internet. He said the data likely came from exported device configurations, warned that attackers could use the credentials to access firewalls and create backdoors, and recommended credential rotation, FortiOS upgrades, MFA, and assuming compromise.
On 2026-06-17, BleepingComputer reported a newly disclosed leak dubbed 'FortiBleed' exposing credentials tied to 73,932 Fortinet firewall URLs across 194 countries. Researcher Bob Diachenko discovered the exposed server, and analysis by Hudson Rock indicated the data included plaintext passwords and operational notes consistent with a large-scale credential-harvesting campaign.
SOCRadar reported an active campaign in which attackers systematically compromised Fortinet FortiGate firewalls and VPN gateways across 194 countries, building a database of 30,791 verified working credentials. The operation reportedly used automated scanning, credential stuffing, brute-force attempts with previously leaked Fortinet passwords, and traffic monitoring on compromised devices to harvest additional credentials.
Unit 42 reported that on 2026-06-16 an initial access broker on the Russian-language forum Exploit[.]in claimed responsibility for the FortiBleed campaign, referenced a CVE, and offered harvested credentials for sale. Unit 42 said it had not validated the actor's claim.
On 2026-06-16, SOCRadar published its report describing the ongoing Fortinet-focused campaign, stating there was no evidence of a Fortinet zero-day or compromise of Fortinet itself. The report said telecom was the most affected sector, identified significant impact on government entities, and recommended password resets, MFA, log review, restricted management exposure, firmware updates, and incident response engagement.
SpyCloud assessed that the FortiBleed operation began on 2026-05-19 as a live initial access broker campaign using mass scanning and credential attacks. The researchers said the actors targeted not only Fortinet FortiGate devices but also Synology DSM, Sophos firewalls, and MSSQL servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
risky.biz
Open sourcecentripetal.ai
Open sourcerhisac.org
Open sourcehackread.com
Open sourceowned.lab6.com
Open sourcecyber.gc.ca
Open sourceapp.flare.io
Open sourcedocs.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.