Massive "FortiBleed" Campaign Compromises Credentials for over 70,000 Fortinet Devices

‘FortiBleed’ Campaign: Over 70,000 Fortinet Firewalls Compromised in Global Credential Heist

CRITICAL
June 19, 2026
5m read
CyberattackData BreachThreat Intelligence

Impact Scope

People Affected

Credentials for 73,932 devices

Industries Affected

GovernmentCritical InfrastructureTelecommunicationsFinanceHealthcareManufacturing

Geographic Impact

United StatesIndiaMexico (global)

Related Entities

Organizations

Fortinet Australian Cyber Security Centre

Products & Tech

FortiGateFortinet SSL VPNHashtopolisActive Directory

Other

Hudson RockKevin Beaumont

Full Report

Executive Summary

A massive and highly automated credential harvesting campaign, dubbed 'FortiBleed', has led to the compromise of administrative and SSL-VPN credentials for at least 73,932 Fortinet FortiGate devices worldwide. The operation, attributed to a Russian-speaking threat group, has affected organizations across 194 countries and over 21,000 unique domains. The attackers conducted a large-scale brute-force and credential stuffing attack, exfiltrated configuration files containing hashed credentials, and cracked them offline. Fortinet has stated this campaign does not leverage a new zero-day vulnerability but instead exploits poor security hygiene, such as weak or reused passwords and the absence of multi-factor authentication (MFA). The breach poses a significant threat, as compromised firewalls provide attackers with a direct entry point into corporate networks, enabling data theft, ransomware deployment, and lateral movement.

Threat Overview

The 'FortiBleed' campaign is a textbook example of leveraging weak credentials at scale. The threat actors systematically targeted internet-facing FortiGate firewalls and SSL-VPN gateways. Their primary method involved:

  1. Mass Scanning & Brute-Force: Conducting over 1.16 billion automated login attempts against FortiGate devices.
  2. Configuration Exfiltration: Stealing configuration files from vulnerable devices.
  3. Offline Hash Cracking: Extracting SSL VPN authentication hashes (sslvpn_websession) from the configuration files and cracking them offline using a powerful 45-GPU cluster managed by Hashtopolis.
  4. Credential Validation & Sale: Verifying the cracked credentials and likely selling them on underground forums or using them for direct network access.

Once initial access was gained via the compromised VPN or administrative accounts, attackers were observed pivoting into internal Active Directory environments to escalate their attacks.

Technical Analysis

The core of the attack does not rely on sophisticated exploits but on fundamental security failings. The attackers targeted the authentication mechanisms of FortiGate devices. The ability to grab configuration files suggests either the use of a prior vulnerability or the successful guessing of administrative credentials.

The most critical component was the offline cracking of password hashes. By exfiltrating the sslvpn_websession hashes, the attackers could use immense computational power without the risk of triggering lockout policies on the target devices. This highlights the danger of storing even hashed credentials in accessible configuration backups.

MITRE ATT&CK Techniques:

  • T1110 - Brute Force: The attackers used brute force and credential stuffing against login interfaces.
  • T1110.002 - Password Cracking: The use of a GPU cluster to crack exfiltrated password hashes offline is a clear example of this technique.
  • T1078 - Valid Accounts: The ultimate goal and result of the campaign is the acquisition of valid administrative and VPN accounts.
  • T1589.002 - Email Addresses: The attackers likely harvested email addresses from previous breaches to use in credential stuffing attacks.
  • T1087.002 - Domain Account: Post-compromise, attackers pivoted to compromise internal Active Directory accounts.

Impact Assessment

The impact of this campaign is severe. A compromised firewall or VPN gateway is one of the most critical security failures an organization can experience. It grants attackers a trusted position on the network perimeter, from which they can:

  • Monitor and Intercept Traffic: Capture sensitive data passing through the firewall.
  • Lateral Movement: Pivot into the internal network to access servers, databases, and workstations.
  • Deploy Ransomware: Use the initial foothold to deploy ransomware across the entire enterprise.
  • Data Exfiltration: Steal intellectual property, customer data, and other sensitive information.

Given the targeting of critical infrastructure, government, and financial services, the potential for widespread disruption and significant financial loss is extremely high. The global scale of the compromise means that secondary attacks stemming from this campaign are likely to be seen for months or even years to come.

IOCs — Directly from Articles

No specific file hashes or C2 domains were mentioned in the source articles.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns to identify related activity:

  • Log Source: FortiGate System and Security Event Logs.
  • Observable: A high volume of failed login attempts from single or multiple IP addresses against the administrative or SSL-VPN interfaces.
  • Observable: Successful logins from geographically anomalous locations or outside of normal business hours.
  • Observable: Any successful login using an account that does not have MFA enabled.
  • Observable: Outbound connections from the FortiGate device to unknown or suspicious IP addresses, which could indicate exfiltration of configuration files.

Detection & Response

  • Audit Logs: Immediately review FortiGate authentication logs for any successful logins that appear suspicious. Cross-reference login source IPs with threat intelligence feeds.
  • Session Review: Terminate all active administrative and VPN user sessions to force re-authentication.
  • EDR/NDR: Monitor internal network traffic for signs of lateral movement originating from IP addresses associated with VPN users. Look for unusual RDP, SMB, or WinRM activity.
  • D3FEND Techniques: Implement D3-DAM: Domain Account Monitoring and D3-LAM: Local Account Monitoring to detect anomalous use of the compromised credentials within the network.

Mitigation

Fortinet and security researchers strongly recommend the following actions:

  1. Enforce MFA: Immediately enable and enforce multi-factor authentication (MFA) for all administrative and SSL-VPN user accounts. This is the single most effective defense against this attack.
  2. Reset All Credentials: Force a password reset for all FortiGate local users, especially administrative and VPN accounts. Ensure new passwords are long, complex, and unique.
  3. Implement Strong Password Policies: Enforce policies that require complex passwords and regular rotation.
  4. Upgrade Firmware: Update all Fortinet devices to the latest recommended firmware version to ensure all known vulnerabilities are patched.
  5. Restrict Access: Limit access to the FortiGate management interface to a trusted set of source IP addresses. Do not expose the management interface directly to the internet if possible.

Timeline of Events

1
June 13, 2026
Security researcher Volodymyr Diachenko first reports on the campaign.
2
June 18, 2026
The Australian Cyber Security Centre issues a critical alert regarding the FortiBleed campaign.
3
June 19, 2026
Fortinet publishes a blog post acknowledging the campaign and providing mitigation guidance.
4
June 19, 2026
This article was published

MITRE ATT&CK Mitigations

Enforcing MFA on all administrative and VPN accounts is the single most effective countermeasure, as it invalidates stolen passwords.

Enforce strong, complex passwords to make brute-forcing and offline cracking significantly more difficult and time-consuming.

Restrict access to the FortiGate management interface to a limited set of trusted IP addresses, reducing the attack surface exposed to the internet.

Audit

M1047enterprise

Regularly audit authentication logs for signs of brute-force attacks or anomalous successful logins to enable early detection.

Keeping FortiGate firmware up-to-date ensures that any past vulnerabilities that could facilitate configuration exfiltration are patched.

D3FEND Defensive Countermeasures

The most critical and immediate action for all Fortinet administrators is to enable and enforce Multi-factor Authentication (MFA) on all administrative and SSL-VPN accounts. The 'FortiBleed' campaign relies entirely on the compromise of single-factor (password-only) authentication. By requiring a second factor, such as a one-time password (OTP) from an authenticator app or a hardware token, stolen or cracked passwords become useless to the attacker. This should be implemented with zero exceptions for all users, including service accounts and high-privileged administrators. This single hardening action effectively neutralizes the primary attack vector used in this campaign and provides a robust defense against future credential-based attacks.

Immediately enforce a strong password policy for all FortiGate local accounts and force a password reset for all users. This policy should mandate a minimum length of 15 characters, including a mix of uppercase letters, lowercase letters, numbers, and symbols. This is crucial because the attackers are performing offline hash cracking. A complex password dramatically increases the time and computational resources required to crack a hash, often making it infeasible. Banning common and previously breached passwords is also recommended. While MFA is the primary defense, a strong password policy serves as a vital layer of defense that hardens the credentials themselves against brute-force and dictionary attacks.

Restrict network access to the FortiGate's management interface (HTTPS, SSH) to a specific, authorized set of IP addresses or subnets, such as a dedicated management network or specific corporate office IPs. The management interface should never be exposed to the entire internet. By implementing a strict allowlist for management access, organizations can drastically reduce the attack surface available for brute-force attempts. This prevents the attackers' automated scanning and login tools from ever reaching the authentication portal, effectively blocking the first stage of the attack. This is a fundamental network hardening practice that should be applied to all critical infrastructure management interfaces.

Timeline of Events

1
June 13, 2026

Security researcher Volodymyr Diachenko first reports on the campaign.

2
June 18, 2026

The Australian Cyber Security Centre issues a critical alert regarding the FortiBleed campaign.

3
June 19, 2026

Fortinet publishes a blog post acknowledging the campaign and providing mitigation guidance.

Sources & References

FortiBleed campaign exposes 75000 Fortinet firewalls worldwide
CSO Online (csoonline.com) June 18, 2026
FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
Recorded Future (recordedfuture.com) June 19, 2026
Top 5 Cybersecurity News Stories June 19, 2026
DieSec (diesec.com) June 19, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Tags

FortiBleedFortinetFortiGateCredential StuffingBrute ForceMFACyberattack

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.