FortiBleed campaign compromised more than 30,000 Fortinet firewalls and VPN gateways worldwide

Researchers say more than 30,000 Fortinet firewalls and virtual private network gateways were compromised and can expose the organizations behind them to further hacking. SOCRadar said a campaign it calls FortiBleed systematically tried known passwords against internet-exposed Fortinet devices, harvested working credentials, then monitored traffic and reused newly captured passwords to spread further; victims span companies and government bodies in more than 190 countries.
Why it matters: Organizations using Fortinet edge devices may already have attackers inside even without a new software flaw. This is urgent for network defenders: audit Fortinet logins, rotate passwords and tokens, review device configurations, and check for signs of credential harvesting or unauthorized access.

Sources

Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together
2026.07.02 95% relevant
This article directly updates the FortiBleed event by linking the credential-harvesting campaign to ransomware operations, reporting that SOC Radar found a shared operator tied to both INC Ransom and Lynx affiliate panels and linked at least 12 ransomware attacks to FortiBleed victims.
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
Ionut Arghire 2026.07.02 95% relevant
This source updates the same FortiBleed campaign by adding evidence that harvested FortiGate credentials were used in follow-on ransomware attacks, specifically linking the operation to INC and Lynx, and adding scope figures on scanned portals, admin compromise, domain takeover, and ransomware deployment.
FortiBleed credential-theft campaign linked to Lynx ransomware
Lawrence Abrams 2026.07.01 98% relevant
This article directly advances the same FortiBleed event by linking the campaign to INC and Lynx ransomware operators, expanding the known scope to 430,000 targeted FortiGate devices and about 19,000 with sniffers deployed, identifying more operational servers, and noting suspected use of an undisclosed Nextcloud zero-day plus persistent backdoor accounts named 'adminin'.
Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory
Arctic Wolf Labs 2026.06.24 95% relevant
This is a direct follow-up on the same FortiBleed campaign and adds concrete reverse-engineering details about the recovered CyberStrike Harvester tool, the operator workflow, credential-stuffing and password-spraying tradecraft, offline cracking pipeline, post-authentication capture processing, and the assessment that the campaign is likely an initial-access and credential-monetization operation rather than one primarily driven by a Fortinet CVE exploit.
Russian Initial Access Broker Behind FortiBleed Campaign
Ionut Arghire 2026.06.23 95% relevant
This is a direct update on the same FortiBleed campaign, adding attribution to a likely Russian-speaking initial access broker, explaining that the operation is multi-vendor rather than Fortinet-only, detailing the custom FortigateSniffer tool and SSH brute-force intrusion method, and expanding the estimated scale to 110 million captured credentials and 430,000 FortiGate devices in scope.
FortiBleed campaign used custom FortiGate sniffer to steal credentials
Lawrence Abrams 2026.06.22 96% relevant
This directly updates the same FortiBleed campaign by adding new findings that the actor used a custom Golang-based sniffer on compromised FortiGate devices to capture RADIUS, NTLM, Kerberos, LDAP, email, database, and other authentication material, reinforcing that the campaign is an ongoing initial-access operation rather than just a dump of old credentials.
Fortinet Responds to FortiBleed Campaign
Ionut Arghire 2026.06.22 98% relevant
This is a direct update on the same FortiBleed campaign, adding Fortinet's response that the activity does not rely on a new vulnerability, ties it to reused credentials and brute-force attacks, cites prior FortiCloud SSO flaws CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719, and says over 86,000 working credentials were compiled across 194 countries.
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
info@thehackernews.com (The Hacker News) 2026.06.19 94% relevant
This appears to be an update on the same FortiBleed campaign, adding CISA warning context and a much larger observed impact count of 86,644 exposed or affected FortiGate devices.
FortiBleed: 86,000 Fortinet Device Credentials Compromised
Ionut Arghire 2026.06.19 98% relevant
This is a direct update on the same FortiBleed campaign, raising the count from more than 30,000 to 86,644 valid credentials, adding CISA hardening guidance, and citing additional validation from Hudson Rock, Huntress, Kevin Beaumont, and Bob Diachenko about scope, recency, and follow-on compromises.
CISA warns Fortinet users to secure devices after FortiBleed leak
Sergiu Gatlan 2026.06.19 97% relevant
This article is a direct update on the same FortiBleed credential-leak campaign, adding CISA's warning and mitigation guidance, an updated scale of roughly 74,000 exposed credentials, and additional reporting that threat actors used the leaked credentials to target internet-accessible Fortinet devices across government and private-sector organizations.
Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries
Arctic Wolf Labs 2026.06.17 98% relevant
This is the same underlying FortiBleed event and adds a defender-focused summary of the scope across 194 countries, the estimate of 30,791 to 75,000 affected devices, and Fortinet-specific mitigation details about legacy SHA-256 password hashes persisting after upgrades unless admins log in or reset passwords.
Massive password-stealing attack hits 75k Fortinet firewalls
2026.06.17 98% relevant
This is the same FortiBleed credential-theft campaign and updates the scope from more than 30,000 to around 75,000 compromised Fortinet devices, adds verification from Hudson Rock and Kevin Beaumont that the credentials are real, and adds details about 21,632 affected domains across 194 countries and at least four full compromises including a Turkish NATO defense contractor.
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
Lawrence Abrams 2026.06.17 96% relevant
This article appears to be a direct update on the same FortiBleed event, adding that an exposed server contained credentials for 73,932 Fortinet/FortiGate VPN URLs, with usernames, email addresses, and plaintext passwords, along with claimed evidence of large-scale brute-force and compromise activity across 194 countries.
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
Eduard Kovacs 2026.06.17 100% relevant
The article introduces a separate, concrete campaign dubbed FortiBleed involving large-scale compromise of Fortinet firewalls and VPN gateways, not just exploitation of the already tracked FortiSandbox CVE story.
← Back to all stories