If you're running Fortinet firewalls or VPN gateways anywhere in your organisation, stop what you're doing and read this. A sweeping, actively ongoing cyber campaign — now dubbed "FortiBleed" — has exposed verified login credentials for tens of thousands of enterprise-grade network devices across the globe. This isn't a theoretical risk. It's a real, right-now threat that demands immediate action.

Here's everything you need to know about what happened, how the attack works, and — most importantly — what you can do about it today.


What Is the FortiBleed Campaign?

In mid-June 2026, security researchers identified an active, large-scale credential compromise campaign affecting Fortinet FortiGate firewalls, dubbed FortiBleed.

The credential harvesting operation is actively targeting Fortinet firewalls and VPN gateways, and has already compromised more than 30,000 internet-facing devices across nearly 200 countries.

Evidence of the credential harvesting was first spotted by security consultant Volodymyr Diachenko. Researchers from SOCRadar uncovered the campaign when they found an exposed operational server belonging to the attackers — suspected Russian-speaking threat actors — giving them visibility into the group's tooling, victim database, automation infrastructure, and verified credential repository.

According to the report, "the attacker's database contains login credentials for more than 30,791 devices belonging to companies and government organisations across 194 countries."

Further analysis by independent researcher Kevin Beaumont and Hudson Rock placed the total number of affected devices even higher.

While SOCRadar initially reported the dataset contained working login credentials for over 30,791 devices, further analysis placed the affected devices at 75,000 — about 50% of the total internet-facing Fortinet firewalls found on Shodan.

Rating the campaign as "critical," SOCRadar published its findings to alert defenders to the ongoing campaign, even though the database has not been offered for sale on any hacker forums to date.


How Did Attackers Pull This Off?

Understanding the attack mechanics is critical, because FortiBleed is not your typical zero-day exploit story.

According to Fortinet, the campaign is not linked to any newly disclosed vulnerability or recent security advisory. Instead, attackers are attempting to reuse credentials collected from historical breaches, demonstrating how old compromised data can continue to create cybersecurity risks for organisations years after the original incidents.

Threat actors leveraged automated scanning to identify Fortinet devices with exposed management interfaces, then extracted configuration files. These files enabled offline credential attacks that bypassed rate-limiting controls typically enforced during live authentication attempts.

What began as large-scale credential stuffing evolved into a self-sustaining harvesting network: compromised devices became sniffers, capturing credentials from passing traffic and feeding them back into the attack loop.

The "Patching Paradox" That Made It Worse

Here's the twist that makes this campaign particularly alarming for security teams: even organisations that applied firmware updates may still be exposed.

Fortinet did migrate to the stronger PBKDF2 hashing algorithm in early 2025, but this only protects accounts whose administrators actively re-authenticated after the firmware update was applied.

Thousands of organisations applied the firmware but left the old, vulnerable hashes sitting in configuration files like ticking time bombs.

Even strong passwords provided no protection in many cases.

Passwords of 25 or more characters, including symbols, numbers, and mixed case, were found in the dataset in plaintext — not cracked, but already known, pulled verbatim from previously harvested infostealer logs. The Hudson Rock analysis flagged this explicitly: a significant volume of highly complex credentials were compromised not through brute force, but because they already existed in infostealer databases.


Who Is at Risk?

The short answer: almost everyone running an internet-facing Fortinet device.

The campaign has been observed impacting tens of thousands of internet-facing Fortinet devices across more than 190 countries, affecting organisations across critical infrastructure, government, and enterprise sectors.

SentinelOne DFIR reported multiple intrusions in which threat actors compromised FortiGate Next-Generation Firewall (NGFW) appliances to gain an initial foothold, then extracted FortiGate configuration files containing service account credentials and network topology data. The activity targeted organisations including healthcare, government, and managed service providers.

The campaign is notable for its focus on high-value targets such as networking devices and VPNs, which serve as critical gateways into enterprise networks and often possess privileged access that can bypass internal security controls. Industries such as manufacturing, industrials, and utilities are particularly at risk due to the potential for operational disruption and rapid financial gain for attackers.

SOCRadar's analysis found that the firewalls and VPNs compromised often had security weaknesses in the targeted network infrastructure. Many were either generic administrator accounts, default or built-in Fortinet system accounts, or long-lived accounts with passwords that had never been rotated after previous incidents.


What Happens After a Device Is Compromised?

Gaining firewall credentials is just the attacker's first step — and what follows can be devastating.

The campaign did not stop at the firewall. Once inside, attackers pivoted directly into internal Active Directory environments — the central directory managing all Windows accounts and permissions across an organisation. From there, they moved laterally through internal networks. At least four organisations were fully compromised, with confirmed lateral movement across Japan, Taiwan, Vietnam, Iraq, and Turkey.

The Canadian Centre for Cyber Security issued Alert AL26-014 warning that exposed Fortinet credentials in the FortiBleed campaign could enable remote access to affected devices and connected networks, and allow attackers to alter security settings.

SentinelOne noted that many affected environments lacked sufficient FortiGate logging, limiting defenders' ability to determine the exact initial access vector and timeline; observed dwell time from perimeter compromise to follow-on internal activity ranged from months to near-immediate escalation.


The Broader Threat Landscape

FortiBleed doesn't exist in a vacuum. It reflects a dangerous and accelerating trend in modern cybercrime.

The latest alert reflects a broader trend in cybercrime, where threat actors increasingly combine stolen credentials, automated password-guessing tools, and large-scale reconnaissance to compromise organisations across multiple industries.

Stolen credential records increased by 500%, with 1.7 billion records shared in underground forums.

In that context, FortiBleed is not an anomaly — it's a symptom of a deeply broken credential hygiene ecosystem.

The FortiBleed playbook — scan, stuff, sniff, feed — will likely be replicated against other network device vendors within 12–18 months.

If you're running Cisco, Palo Alto, or SonicWall perimeter devices and thinking "this isn't my problem," it's time to reconsider.


Practical Tips: How to Protect Your Network Right Now

Don't wait for a breach notification. Here are the concrete steps every network administrator and security team should take immediately:

🔑 1. Rotate ALL Credentials Immediately

Reset every administrator, local user, and SSL VPN credential on affected devices immediately. Because FortiBleed is credential-driven, a patched firewall with an unchanged password is still exposed.

Pay particular attention to generic "admin" accounts and built-in system accounts.

🔒 2. Enforce Multi-Factor Authentication (MFA)

Deploy phishing-resistant MFA such as FIDO2 or certificate-based authentication. This renders stolen credentials ineffective even if attackers possess valid usernames and passwords.

🛠️ 3. Patch and Verify Your FortiOS Version

The core protective steps include upgrading FortiOS to 7.2.11, 7.4.8, 7.6.1 or later, and requiring all administrators to log in post-upgrade to re-hash stored credentials with PBKDF2.

Patching without forcing a re-authentication still leaves old credential hashes vulnerable.

🚫 4. Remove Management Interfaces from Public Internet

Administrators should ensure that Fortinet management interfaces are not exposed to the public internet. Access should be restricted to trusted internal networks, and any unnecessary or unauthorised accounts must be removed immediately.

🔍 5. Hunt for Indicators of Compromise

Audit for unauthorised accounts such as "forticloud-sync" and "forticloud-tech," restrict management access, terminate active sessions, reset passwords, enforce MFA, update firmware, and verify patches for CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719.

Organisations are advised to conduct thorough log reviews, including analysing firewall logs, VPN access records, authentication logs, and domain controller activity for signs of suspicious behaviour.

🏗️ 6. Move Toward Zero Trust Architecture

Replace or supplement SSL-VPN with Zero Trust Network Access (ZTNA) solutions that authenticate users and devices continuously, rather than relying on a single perimeter gateway. Ensure that compromised edge devices cannot provide unrestricted access to internal networks.

📡 7. Monitor Credentials in Breach Feeds

A vulnerability may exist only for a short time, but stolen credentials can provide access for months or years.

Subscribe to threat intelligence services that monitor dark web and infostealer breach feeds for your organisation's credentials so you can respond before attackers do.


Conclusion: Your Perimeter Is Being Tested Right Now

FortiBleed is a wake-up call that no security team can afford to ignore.

The campaign underscores the growing risk of credential-based attacks, particularly as threat actors increasingly rely on stolen login data rather than exploiting software vulnerabilities. It also highlights the importance of proactive security measures, including strong authentication, proper credential management, and continuous monitoring.

Organisations must assume that similar operations are running undetected right now, targeting every vendor, every device, every perimeter. The question isn't whether you'll be targeted — it's whether you'll detect it before the attackers achieve their objectives.

Don't leave your network's security to chance. If your organisation relies on Fortinet devices and you haven't yet taken the steps outlined above, now is the time to act. Contact your managed security provider, conduct an immediate audit of your FortiGate estate, and implement the mitigations in this guide today. A credential reset costs an hour of downtime. A full network compromise costs everything.