LIVE · cybersecurity feed
Live wire
fortinetcritical

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems

A campaign dubbed FortiBleed has exposed administrative and VPN credentials for over 73,000 FortiGate systems. The compromised data has been offered for sale by at least two threat actors, one of whom is considered credible by researchers, while the other is suspected of attempting to re-extort victims. The exposed credentials impact organizations across various sectors, including government and critical infrastructure.

zeroday.news · 38d ago

A campaign dubbed "FortiBleed" has exposed administrative and VPN credentials for an estimated 73,932 FortiGate firewall systems globally. The compromised data, reportedly originating from a Russian-speaking threat group, has impacted organizations across critical sectors including government, telecommunications, financial services, healthcare, manufacturing, and multinational corporations.

Security researcher Volodymyr Diachenko first reported on the dataset on June 13, 2026, attributing it to a Russian-speaking threat actor. Subsequent analysis by cybersecurity researcher Kevin Beaumont and threat intelligence firm Hudson Rock validated portions of the dataset, with Beaumont confirming the authenticity of sampled administrative credentials. Many of the affected devices were reportedly still online and running recent versions of FortiOS, with their management interfaces exposed to the internet at the time of disclosure.

The scale of the exposure is significant, with the dataset allegedly containing credentials for systems in 194 countries. Confirmed or reported compromises include organizations in Japan, Taiwan, Vietnam, Iraq, and Türkiye. Notably, a Turkish NATO defense contractor is among those affected, with threat actors allegedly exfiltrating classified documents from the compromised system.

According to Diachenko's investigation, the threat actors conducted approximately 1.16 billion credential attempts against FortiGate targets and an additional 2.1 billion attempts against Microsoft SQL Server systems. They reportedly intercepted SSL VPN authentication hashes and utilized a 45-GPU cluster managed through Hashtopolis to crack these hashes, recovering plaintext credentials. Researchers believe the dataset likely originated from exported FortiGate configuration files, allowing for offline credential recovery without continuous access to the targeted devices.

Threat intelligence firm Insikt Group identified malicious activity associated with the IP address 85.11.187.8, linked to the FortiBleed attacks. Their analysis revealed artifacts consistent with credential harvesting and intrusion activities, including a sniffer log for Fortinet credential capture, cracking orchestration files, Active Directory enumeration scripts, password-spraying tools, and SMB/DFS collection scripts with exfiltration capabilities. Evidence of log-clearing markers was also present, suggesting attempts to cover tracks. A PwnDefend blog post on June 18, 2026, corroborated the association of this IP address with the campaign.

The FortiBleed campaign is considered high-priority due to the independently verified authenticity of a subset of credentials, the ongoing exposure of many affected devices, and the sheer scale of the incident. The attribution to a Russian-speaking group and the confirmed targeting of a NATO defense contractor raise concerns about potential espionage objectives.

The timeline of events began on June 13, 2026, with Diachenko's public report. On the same day, Kevin Beaumont published his analysis confirming the credentials, and Hudson Rock validated parts of the dataset, releasing a lookup tool for organizations to check for exposure.

Insikt Group also noted that at least two threat actors are attempting to profit from the FortiBleed data. One seller, operating under the moniker "SantaAd" on an exploit forum, advertised auctioning 34,000 lines of FortiGate VPN data on June 12, 2026. Insikt Group assesses this seller as likely credible, though they did not observe a sample to confirm it was the same data involved in the FortiBleed incident.

A second seller, identified as "shinymontanna" within a public Telegram channel and leveraging the ShinyHunters branding, was identified on June 21, 2026. This seller is reportedly reusing language from SantaAd's post and is assessed by Insikt Group as likely attempting to re-extort victims, a tactic they have employed previously. Shinymontanna has been active since at least late 2025, engaging in extortion attempts with ransom demands ranging from $100,000 to $2 million.

Organizations running Fortinet products are advised to immediately rotate all FortiGate administrative and SSL VPN credentials. They should also enforce multi-factor authentication for all remote and administrative access, review Fortinet logs for suspicious activity, and consider replacing devices with confirmed suspicious activity. Restricting internet exposure for management interfaces, patching FortiOS, and reviewing hardening settings are also recommended. Furthermore, organizations should hunt for downstream compromise within their networks if exposed credentials were in use.

fortinetfortigatecredentialsdata breachthreat actors
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]