Find notable cyber news and cases, enriched with sources, timelines, and signals.
Data Leak

FortiBleed Credential Exposure Affecting FortiGate and SSL VPN Accounts

Updated 22.06.2026 11:30
Case score 93
Case score 93 Members 1 Latest activity 22.06.2026 11:30
Members 1 First seen 22.06.2026 11:30 Last seen 22.06.2026 11:30 Updated 22.06.2026 11:30

Overview

A **FortiBleed** dataset containing around **75,000 stolen credentials** tied to **FortiGate firewall and SSL VPN** customers has been exposed, putting affected organizations at immediate risk of account takeover and follow-on network access. The leaked records reportedly include usernames, email addresses, and plaintext passwords, and the exposure has been associated with customers in **194 countries** and **over 21,000 unique domains**. The initial intrusion method has not been confirmed, but the reported sequence points to stolen configuration data followed by credential abuse opportunities against internet-facing systems. The UK **NCSC** has already issued guidance telling affected organizations to check exposure and review for indicators such as unauthorized account creation and unexpected log activity.

Signals

4 derived
Impact signals
Affected impact
Exposed data
Data exposure
Leak status Fully Leaked Data Email Addresses Data Usernames

Malware context

0 families · 1 tools
Tools
FortiBleed checker tools

Member happenings

1 related
Data Leak FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Updated 22.06.2026 11:30 Lead Contribution 93
Data Type Email Addresses Data Type Usernames Data Status Fully Leaked

The **FortiBleed** credential leak exposed **around 75,000 stolen logins** from **FortiGate firewall and SSL VPN customers**, creating immediate account-takeover risk for affected organizations. The exposed records include **usernames, email addresses, and plaintext passwords** tied to customers in **194 countries**. The dataset also spans **over 21,000 unique domains**, showing broad exposure across internet-facing Fortinet deployments. The UK’s **NCSC** has issued guidance for impacted customers to check exposure and hunt for compromise indicators.