A campaign dubbed "FortiBleed" has exposed administrative and VPN credentials for an estimated 73,932 FortiGate firewall systems globally. The compromised data, reportedly originating from a Russian-speaking threat group, has impacted organizations across critical sectors including government, telecommunications, financial services, healthcare, manufacturing, and multinational corporations.
Security researcher Volodymyr Diachenko first reported on the dataset on June 13, 2026, attributing it to a Russian-speaking threat actor. Subsequent analysis by cybersecurity researcher Kevin Beaumont and threat intelligence firm Hudson Rock validated portions of the dataset, with Beaumont confirming the authenticity of sampled administrative credentials. Many of the affected devices were reportedly still online and running recent versions of FortiOS, with their management interfaces exposed to the internet at the time of disclosure.
The scale of the exposure is significant, with the dataset allegedly containing credentials for systems in 194 countries. Confirmed or reported compromises include organizations in Japan, Taiwan, Vietnam, Iraq, and Türkiye. Notably, a Turkish NATO defense contractor is among those affected, with threat actors allegedly exfiltrating classified documents from the compromised system.
According to Diachenko's investigation, the threat actors conducted approximately 1.16 billion credential attempts against FortiGate targets and an additional 2.1 billion attempts against Microsoft SQL Server systems. They reportedly intercepted SSL VPN authentication hashes and utilized a 45-GPU cluster managed through Hashtopolis to crack these hashes, recovering plaintext credentials. Researchers believe the dataset likely originated from exported FortiGate configuration files, allowing for offline credential recovery without continuous access to the targeted devices.
Threat intelligence firm Insikt Group identified malicious activity associated with the IP address 85.11.187.8, linked to the FortiBleed attacks. Their analysis revealed artifacts consistent with credential harvesting and intrusion activities, including a sniffer log for Fortinet credential capture, cracking orchestration files, Active Directory enumeration scripts, password-spraying tools, and SMB/DFS collection scripts with exfiltration capabilities. Evidence of log-clearing markers was also present, suggesting attempts to cover tracks. A PwnDefend blog post on June 18, 2026, corroborated the association of this IP address with the campaign.
The FortiBleed campaign is considered high-priority due to the independently verified authenticity of a subset of credentials, the ongoing exposure of many affected devices, and the sheer scale of the incident. The attribution to a Russian-speaking group and the confirmed targeting of a NATO defense contractor raise concerns about potential espionage objectives.
The timeline of events began on June 13, 2026, with Diachenko's public report. On the same day, Kevin Beaumont published his analysis confirming the credentials, and Hudson Rock validated parts of the dataset, releasing a lookup tool for organizations to check for exposure.
Insikt Group also noted that at least two threat actors are attempting to profit from the FortiBleed data. One seller, operating under the moniker "SantaAd" on an exploit forum, advertised auctioning 34,000 lines of FortiGate VPN data on June 12, 2026. Insikt Group assesses this seller as likely credible, though they did not observe a sample to confirm it was the same data involved in the FortiBleed incident.
A second seller, identified as "shinymontanna" within a public Telegram channel and leveraging the ShinyHunters branding, was identified on June 21, 2026. This seller is reportedly reusing language from SantaAd's post and is assessed by Insikt Group as likely attempting to re-extort victims, a tactic they have employed previously. Shinymontanna has been active since at least late 2025, engaging in extortion attempts with ransom demands ranging from $100,000 to $2 million.
Organizations running Fortinet products are advised to immediately rotate all FortiGate administrative and SSL VPN credentials. They should also enforce multi-factor authentication for all remote and administrative access, review Fortinet logs for suspicious activity, and consider replacing devices with confirmed suspicious activity. Restricting internet exposure for management interfaces, patching FortiOS, and reviewing hardening settings are also recommended. Furthermore, organizations should hunt for downstream compromise within their networks if exposed credentials were in use.






