Find notable cyber news and cases, enriched with sources, timelines, and signals.
Data Leak

FortiBleed Credential Exposure Affecting FortiGate and SSL VPN Accounts

Updated 22.06.2026 11:30
Case score 93
Members 1 First seen 22.06.2026 11:30 Latest activity 22.06.2026 11:30

Overview

A **FortiBleed** dataset containing around **75,000 stolen credentials** tied to **FortiGate firewall and SSL VPN** customers has been exposed, putting affected organizations at immediate risk of account takeover and follow-on network access. The leaked records reportedly include usernames, email addresses, and plaintext passwords, and the exposure has been associated with customers in **194 countries** and **over 21,000 unique domains**. The initial intrusion method has not been confirmed, but the reported sequence points to stolen configuration data followed by credential abuse opportunities against internet-facing systems. The UK **NCSC** has already issued guidance telling affected organizations to check exposure and review for indicators such as unauthorized account creation and unexpected log activity.
Latest development Open development history 1 earlier development Security researchers discover stolen FortiGate and SSL VPN credentials database Security researchers discovered a database containing around 75,000 credentials stolen from FortiGate firewall and SSL VPN customers, including usernames, email addresses and plaintext passwords tied to organizations such as Oracle, Spotify, Toyota and AT&T. The exposed logins were said to affect customers in 194 countries and over 21,000 unique domains, creating account-takeover risk for any organization listed in the dataset.
  1. Earlier development

    NCSC issues FortiBleed guidance for Fortinet customers

    The UK’s National Cyber Security Centre issued guidance for Fortinet customers affected by the credential theft campaign, recommending Hudson Rock’s or SOCRadar’s FortiBleed checker tools and checks for indicators of compromise such as unauthorized account creation and unexpected log activity. The guidance was aimed at organizations whose FortiGate and SSL VPN credentials may have been exposed.

Signals

Impact signals
Affected impact
Data exposure

Tooling context

1 tools
Tools

Member happenings

Data Leak FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Updated 22.06.2026 11:30 Lead Contribution 93
Data Type Email Addresses Data Type Usernames Data Status Fully Leaked

The **FortiBleed** credential leak exposed **around 75,000 stolen logins** from **FortiGate firewall and SSL VPN customers**, creating immediate account-takeover risk for affected organizations. The exposed records include **usernames, email addresses, and plaintext passwords** tied to customers in **194 countries**. The dataset also spans **over 21,000 unique domains**, showing broad exposure across internet-facing Fortinet deployments. The UK’s **NCSC** has issued guidance for impacted customers to check exposure and hunt for compromise indicators.