Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-access-methodperimeter-device-exposuremass-credential-exposuretelecommunications-sector-threat

Credential-Harvesting Campaign Compromises 30,000 Fortinet Firewalls

Updated 15h agoFirst seen Jun 17, 202649 sources

A large-scale credential-harvesting campaign has compromised more than 30,000 Fortinet FortiGate firewalls and VPN gateways across 194 countries, according to SOCRadar, which said the attackers amassed a database of 30,791 verified working credentials. Researchers said the operation targeted internet-facing Fortinet management and VPN interfaces using credential stuffing, password spraying, brute-force attempts, and reused passwords from prior leaks, and found no evidence of a Fortinet zero-day or a breach of Fortinet itself.

The attackers allegedly used compromised devices as listening posts to capture additional credentials and feed them into an automated attack chain, broadening access across sectors including telecommunications, government, healthcare, finance, education, energy, and other critical infrastructure. Telecom was reported as the most affected sector, while government entities accounted for 591 entries across 111 domains; India and the United States represented nearly one-third of identified compromises. SOCRadar said the campaign remained active and assessed it as critical, with tooling and victim selection described as consistent with Russian-speaking threat actors and possible motives spanning both financial gain and cyberespionage.

Share:
Credential-Harvesting Campaign Compromises 30,000 Fortinet Firewalls
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

16 events from the most recent confirmed update back to the earliest known activity.

16 EVENTS
Jun 19, 20262d ago

Fortinet confirms credential campaign and begins notifying affected customers

On 2026-06-19, Fortinet said the reported FortiBleed activity was a credential-harvesting campaign using reused credentials and brute-force attacks, not a new Fortinet vulnerability or recent Fortinet incident. The company said it had identified potentially compromised systems, launched an investigation with relevant government agencies, and was proactively notifying affected customers while urging credential resets, MFA, and hardening.

Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog

CloudSEK revises FortiBleed victim counts after attacker server analysis

On 2026-06-19, CloudSEK published a technical analysis of an exposed FortiBleed attacker back-end and said the campaign was a credential-compromise operation rather than a Fortinet zero-day. The firm said widely cited victim totals were overstated, assessing that 918 organizations showed captured internal Kerberos traffic and only 148 represented confirmed compromises with cracked and verified Active Directory credentials.

Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind | CloudSEK

Recorded Future links FortiBleed activity to IP and attacker tooling

Recorded Future’s Insikt Group linked FortiBleed-related activity to IP address 85[.]11[.]187[.]8 and reported infrastructure and tooling consistent with credential harvesting, hash cracking, password spraying, Active Directory enumeration, SMB/DFS collection, staged exfiltration, and log clearing. The report also reiterated attribution to a Russian-speaking threat group and urged immediate credential rotation, MFA enforcement, hardening, and investigation for downstream compromise.

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
Jun 18, 20263d ago

Researchers attribute FortiBleed campaign to Russian-speaking crime group

On 2026-06-18, GovInfoSecurity reported researcher Volodymyr Diachenko's attribution of the FortiBleed-related operation to a Russian-speaking multi-operator cybercrime group. The report said the group intercepts SSL VPN authentication, cracks harvested hashes with a Hashtopolis-managed GPU cluster, and pivots from compromised Fortinet devices into internal Active Directory environments.

Crime Gang Sells Access to 74,000 Fortinet Firewall Devices

CISA urges hardening Fortinet devices after FortiBleed reports

On 2026-06-18, CISA warned that malicious actors were targeting internet-accessible Fortinet devices in government and private sector organizations using compromised credentials associated with FortiBleed. CISA said the exposure involved roughly 74,000 Fortinet devices and urged organizations to terminate active sessions, reset VPN and admin passwords, enforce phishing-resistant MFA, verify PBKDF2 credential storage, review logs, and restrict public internet management access.

CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure | CISA

Canadian Centre for Cyber Security issues FortiBleed alert

On 2026-06-18, the Canadian Centre for Cyber Security issued Alert AL26-014 warning that exposed Fortinet credentials in the FortiBleed campaign could enable remote access to affected devices and connected networks and allow attackers to alter security settings. The agency advised auditing for unauthorized accounts such as "forticloud-sync" and "forticloud-tech," restricting management access, terminating active sessions, resetting passwords, enforcing MFA, updating firmware, and verifying patches for CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719.

AL26-014 - FortiBleed leak of thousands of compromised credentials impacting Fortinet devices - Malware News - Malware Analysis, News and Indicators

UK NCSC issues alert on Fortinet targeting and response guidance

On 2026-06-18, the UK National Cyber Security Centre warned that Fortinet firewalls and VPN gateways were being globally targeted and said there were some indications of potential impact in the UK. The agency advised organizations to investigate for compromise, isolate affected devices, collect forensic artefacts before factory reset, enforce MFA, update or remove unsupported systems, and review for persistence and lateral movement.

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways | National Cyber Security Centre

SOCRadar raises FortiBleed compromise count to more than 86,000 devices

A June 18 report said the FortiBleed campaign had successfully compromised more than 86,000 internet-exposed Fortinet firewall and VPN gateway devices across 194 countries. The report said the operation continued using password-based access and adversary-in-the-middle interception rather than a Fortinet breach or zero-day.

FortiBleed Credential Theft Campaign Marches On - Decipher
Jun 17, 20264d ago

TechCrunch names major companies allegedly affected by FortiBleed

On 2026-06-17, TechCrunch reported that organizations including Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC were among the alleged victims of the FortiBleed campaign targeting exposed Fortinet firewalls and VPNs. The report attributed the victim list to Hudson Rock and SOCRadar's analysis of the broader credential-harvesting operation.

Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world | TechCrunch

Researchers confirm downstream intrusions tied to FortiBleed campaign

Researchers reported that the FortiBleed campaign led to confirmed follow-on compromises at organizations in multiple countries, including persistence, lateral movement, and document exfiltration. The reference specifically cites a Turkish NATO defense contractor among the affected organizations.

FortiBleed: How 75,000 Fortinet Firewalls Were Silently Compromised in 2026 | The CyberSec Guru

Kevin Beaumont reports 75,000 Fortinet firewalls with exposed admin credentials

On 2026-06-17, Kevin Beaumont reported that a recent dataset containing plaintext or crackable administrator credentials for about 75,000 Fortinet firewall devices appeared legitimate, with many affected devices still online and exposing management interfaces to the internet. He said the data likely came from exported device configurations, warned that attackers could use the credentials to access firewalls and create backdoors, and recommended credential rotation, FortiOS upgrades, MFA, and assuming compromise.

FortiBleed - 75k Fortinet firewalls have admin passwords cracked | by Kevin Beaumont | Jun, 2026 | DoublePulsar

Researchers disclose exposed 'FortiBleed' dataset of Fortinet credentials

On 2026-06-17, BleepingComputer reported a newly disclosed leak dubbed 'FortiBleed' exposing credentials tied to 73,932 Fortinet firewall URLs across 194 countries. Researcher Bob Diachenko discovered the exposed server, and analysis by Hudson Rock indicated the data included plaintext passwords and operational notes consistent with a large-scale credential-harvesting campaign.

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
Jun 16, 20264d ago

Threat actor compromises 30,791 Fortinet devices in global credential campaign

SOCRadar reported an active campaign in which attackers systematically compromised Fortinet FortiGate firewalls and VPN gateways across 194 countries, building a database of 30,791 verified working credentials. The operation reportedly used automated scanning, credential stuffing, brute-force attempts with previously leaked Fortinet passwords, and traffic monitoring on compromised devices to harvest additional credentials.

The Compromise of 30,000 Fortinet Firewalls

Initial access broker claims FortiBleed activity on Exploit.in

Unit 42 reported that on 2026-06-16 an initial access broker on the Russian-language forum Exploit[.]in claimed responsibility for the FortiBleed campaign, referenced a CVE, and offered harvested credentials for sale. Unit 42 said it had not validated the actor's claim.

Threat Brief: Mitigating Large-Scale Credential Attacks

SOCRadar publishes findings on Fortinet credential-harvesting campaign

On 2026-06-16, SOCRadar published its report describing the ongoing Fortinet-focused campaign, stating there was no evidence of a Fortinet zero-day or compromise of Fortinet itself. The report said telecom was the most affected sector, identified significant impact on government entities, and recommended password resets, MFA, log review, restricted management exposure, firmware updates, and incident response engagement.

The Compromise of 30,000 Fortinet Firewalls
May 19, 20261mo ago

SpyCloud dates FortiBleed campaign start and multi-platform targeting

SpyCloud assessed that the FortiBleed operation began on 2026-05-19 as a live initial access broker campaign using mass scanning and credential attacks. The researchers said the actors targeted not only Fortinet FortiGate devices but also Synology DSM, Sophos firewalls, and MSSQL servers.

FortiBleed: Analysis of a Global Access Broker Campaign
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

136 LINKEDOpen in app
Threat actors
3 linked
Affected products
21 linked
FortiosFortigateActive DirectoryHashtopolisFortisandboxPan-OsForticlient EmsGlobalprotectFortinet FirewallTelegramCloudflaredUnified Communications ManagerBraveWindows 8SplunkDiskstation ManagerOpenvpnOpnsenseCursorChromiumPanorama
Organizations
73 linked
FortinetHudson RockSophosSecurity AffairsNvidiaRansomnewsSecurityDiscovery.comSOCRadarFoxconnSamsung ElectronicsSiemensComcastAccentureOracleLenovoShodanPricewaterhouseCoopersChevronHunt IntelligenceArctic WolfAT&TMicrosoft CorporationMercedes-BenzToyota Motor CorporationMediumCisco SystemsBleepingComputerLinkedinPalo Alto NetworksDark ReadingVast.aiHashtopolisSpotifyThe RegisterSplunkTaniumAmazon Web ServicesTechCrunchInfosysFedexDefusedCloudflareRecorded FutureBharti AirtelSynologySpyCloudBlackberryBeazley SecuritySinopecCursorCloudSEKDHLHuntressPwnDefendTelmexFlareSecurityOnline.infoOpenvpnS-RMGoogleIPinfoTechGuard SecurityITProDoublePulsarSecure.comGuruculSony Group CorporationWaterISACTech TimesPxWHudsonRockViewDNS.infoOneTwoTrip
Breaches
32 linked
FOXCONN-2026-06SAMSUNG-2026-06ORACLE-2026-06SIEMENS-2026-06COMCAST-2026-06LENOVO-2026-06ACCENTURE-2026-06FORTINET-2026-06CHEVRON-2026-06PWC-2026-06ATT-2026-06MERCEDES-BENZ-2026-06TOYOTA-2026-06TURKISHNATODEFENSECONTRACTOR-2026-06PRICEWATERHOUSECOOPERS-2026-06DHL-2026-04SPOTIFY-2026-04STATEGRID-2026-06SINOPEC-2026-06FORTINETFORTIGATECUSTOMERS-2026-06FORTINETCUSTOMERS-2026-06SPOTIFY-2026-06SONY-2026-06FEDEX-2026-06FORTINETDEVICEUSERSWORLDWIDE-2026-06INFOSYS-2026-06DHL-2026-06CHEVRON-2026-01TURKISHNATODEFENSECONTRACTOR-2026-01FORTINET-2026-01ORGANIZATIONSUSINGFORTINETFIREWALLDEVICES-2026-06FORTINETFORTIGATEUSERS-2026-06
SOURCE COVERAGE

Sources

49 references tracked. Mallory keeps watching after this page renders.

49 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Credential-Harvesting Campaign Compromises 30,000 Fortinet Firewalls | Mallory