VYPR
breachPublished Jun 18, 2026· Updated Jun 23, 2026· 14 sources

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices

A data leak dubbed 'FortiBleed' has exposed VPN credentials for 73,932 Fortinet and FortiGate firewall URLs globally, posing immediate risk of unauthorized network access.

A newly discovered data leak dubbed 'FortiBleed' has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. The leaked data includes device IP addresses, usernames, and passwords, potentially allowing attackers to gain unauthorized access to affected networks. The scale of the leak suggests a coordinated credential-harvesting operation targeting Fortinet's widely deployed VPN infrastructure.

The leaked dataset was first identified by security researchers monitoring underground forums and data leak sites. According to the researchers, the credentials appear to have been collected through a combination of brute-force attacks, exploitation of known vulnerabilities, and possibly insider access. The data includes entries from organizations across multiple sectors, including government, finance, healthcare, and critical infrastructure.

Fortinet has not yet issued an official statement regarding the FortiBleed leak, but the company's security advisory team is reportedly investigating the incident. In the meantime, security experts are urging all organizations using Fortinet VPNs to immediately rotate credentials, enable multi-factor authentication (MFA), and review logs for signs of unauthorized access. The leak underscores the persistent threat posed by credential theft and the importance of robust authentication practices.

The FortiBleed incident follows a pattern of large-scale credential leaks targeting VPN appliances, which have become prime targets for attackers seeking persistent access to corporate networks. Earlier this year, a separate campaign compromised over 30,000 Fortinet devices in a credential-harvesting operation attributed to a Russian-speaking threat actor. While it is unclear if FortiBleed is related to that campaign, the overlap in targeting suggests a sustained interest in Fortinet infrastructure.

Organizations affected by the leak should also consider implementing network segmentation, monitoring for anomalous VPN usage, and conducting thorough forensic investigations to determine if any unauthorized access has occurred. The leak serves as a stark reminder that VPN credentials remain a critical attack surface, and that proactive security measures are essential to mitigate the risk of breach.

As the investigation into FortiBleed continues, the cybersecurity community is closely watching for any additional data dumps or threat actor claims. The incident highlights the ongoing challenge of securing remote access infrastructure in an era of widespread credential theft and automated exploitation.

The leaked dataset, which includes credentials from nearly 74,000 Fortinet firewalls and VPN gateways, was accidentally exposed by the Russian-speaking group on a server and discovered by security researcher Volodymyr Diachenko. Hudson Rock has launched a look-up tool for organizations to check exposure, and researchers confirmed that many high-profile entities such as Samsung, Siemens, Foxconn, Oracle, Accenture, DHL, Infosys, and Fortinet itself are affected. At least four organizations across Japan, Taiwan/Vietnam, Iraq, and Turkey were fully compromised, including a Turkish NATO defense contractor whose classified documents were exfiltrated. Fortinet believes the data was collected via previous incidents and brute-forcing, and Beaumont noted that many devices still use the older, weaker SHA-256 password storage method, making them vulnerable to cracking.

The UK's National Cyber Security Centre (NCSC) has now issued an official advisory warning that the same leaked credential database — dubbed FortiBleed — is being actively used in a global campaign targeting Fortinet firewalls and VPN gateways, with indications of potential impact on UK organizations. The NCSC recommends that affected organizations use Hudson Rock's FortiBleed Checker to assess compromise, isolate and factory-reset devices, and enforce multi-factor authentication alongside firmware updates. This marks the first government-level response to the leak, elevating the threat from a credential exposure to a confirmed active exploitation campaign.

The GovInfoSecurity report adds that the campaign is still active, with attackers processing 1.16 billion credential attempts against 320,777 FortiGate targets and 2.1 billion attempts against 163,650 MSSQL servers, according to researcher Volodymyr Diachenko. Victims now include a Turkish NATO defense contractor whose classified documents were exfiltrated, and the dataset has been verified as real by Kevin Beaumont, who noted that most affected devices remain internet-connected and that attackers are likely exploiting config files from devices that never logged in after a firmware update.

CISA has now issued an urgent advisory urging immediate hardening of Fortinet devices in response to the FortiBleed campaign, which has exposed credentials for approximately 74,000 devices including FortiGate firewalls and SSL VPN gateways. The agency recommends terminating all active sessions, resetting VPN and admin passwords, enforcing PBKDF2 for credential storage, and enabling phishing-resistant MFA to mitigate the ongoing threat.

CISA has now publicly urged Fortinet customers to secure their devices following the leak, recommending immediate enforcement of multi-factor authentication, password rotation for all VPN and admin accounts, patching of FortiOS against known CVEs, and audit log review for signs of unauthorized access. The agency emphasized that affected users should assume compromise and take proactive containment steps, reflecting the escalating concern over the nearly 74,000 exposed credentials fueling follow-on attacks.

SecurityWeek reports that the FortiBleed campaign has now compromised credentials from approximately 86,000 internet-accessible Fortinet firewalls and VPNs, affecting roughly half of all such devices globally. This updated figure surpasses the earlier count of 73,932 devices, indicating the campaign is ongoing and expanding. Fortinet administrators are urged to audit accounts, rotate credentials, and apply available patches to mitigate the threat.

CISA has now issued an urgent advisory amplifying the FortiBleed response, urging organizations to harden internet-facing Fortinet devices by terminating active VPN sessions, resetting passwords, enforcing PBKDF2 hashing, and deploying phishing-resistant MFA. The agency's guidance comes after the initial leak of 74,000 FortiGate credentials was leveraged by attackers to bypass security controls and move laterally across networks. CISA's involvement marks a significant escalation in official response, warning that no specific CVE is required when valid stolen credentials are the attack vector.

CISA has now issued an urgent advisory for the FortiBleed campaign, warning that Russian-speaking threat actors have compromised 86,644 FortiGate devices—up from the 73,932 initially reported. The agency recommends immediately terminating all active SSL VPN and administrative sessions, resetting all passwords, and enforcing PBKDF2-based password hashing to replace legacy SHA-256 storage. The U.K. NCSC also weighed in, characterizing FortiBleed as a global credential-stuffing and brute-force campaign that exploits older credential hashing mechanisms within FortiGate configuration files.

The UK National Cyber Security Centre (NCSC) has now issued formal guidance for Fortinet customers affected by the FortiBleed campaign, urging immediate patching and mitigation to prevent further compromise. The advisory specifically warns that the campaign is targeting critical infrastructure organizations, underscoring the elevated risk beyond credential theft. This marks the first major government-led response to the leak, which exposed VPN credentials for over 73,000 Fortinet and FortiGate firewall URLs globally.

Fortinet has now officially responded to the FortiBleed campaign, stating that the credential harvesting does not exploit new vulnerabilities but instead relies on stolen credentials from previous incidents and brute-force attacks against devices lacking multi-factor authentication (MFA) and strong password policies. The company has identified potentially compromised systems, begun notifying impacted customers, and is working with law enforcement. Additionally, Fortinet has released guidance for affected customers, advising them to terminate admin and VPN sessions, rotate credentials, implement MFA, and upgrade to software releases supporting PBKDF2 hashing of administrator credentials.

The article adds that Fortinet and researchers now attribute the breach to credential reuse and brute-force attacks, not zero-day exploits, and details the use of a Golang-based sniffer tool called FortigateSniffer. It also reports that a threat actor is selling access to 35,000 gateways for $25,000, and that the credential count has grown to over 86,000, with new devices still being added.

SOCRadar's latest report identifies the campaign operators as an initial access broker that deploys a custom Golang tool called 'FortigateSniffer' to abuse the built-in FortiOS 'diagnose sniffer packet' command. The sniffer harvests credentials from 24 protocols including RADIUS, NTLM, Kerberos, and LDAP, which are then cracked using a 36-GPU cluster rented from a GenAI company. The report also describes a Python-based PCAP Deep Analysis Toolkit that extracts cleartext credentials and generates Hashcat-ready hashes, adding technical depth to the previously disclosed credential leak.

New honeypot telemetry reveals that the FortiBleed campaign is just one facet of a broader assault on edge devices, with SSL-VPN appliances from Check Point, Cisco, Ivanti/Pulse, Palo Alto, OpenVPN, and SonicWall also being heavily scanned and targeted for credential harvesting. Experts warn that the Fortinet-focused leak is the 'tip of the iceberg' of a sustained, multi-vendor campaign against perimeter infrastructure, suggesting that organizations relying on any VPN or edge device should treat the threat as systemic rather than isolated.

Synthesized by Vypr AI