Data Leak
FortiBleed Credential Exposure Affecting FortiGate and SSL VPN Accounts
Updated 22.06.2026 11:30
Case score 93
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 93
- Main story score
- 93
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Data Leak Primary incident covering the exposed credential dataset, stated scale, downstream access risk, and immediate defensive guidance. main
Members 1
First seen 22.06.2026 11:30
Latest activity 22.06.2026 11:30
Overview
A **FortiBleed** dataset containing around **75,000 stolen credentials** tied to **FortiGate firewall and SSL VPN** customers has been exposed, putting affected organizations at immediate risk of account takeover and follow-on network access. The leaked records reportedly include usernames, email addresses, and plaintext passwords, and the exposure has been associated with customers in **194 countries** and **over 21,000 unique domains**.
The initial intrusion method has not been confirmed, but the reported sequence points to stolen configuration data followed by credential abuse opportunities against internet-facing systems. The UK **NCSC** has already issued guidance telling affected organizations to check exposure and review for indicators such as unauthorized account creation and unexpected log activity.
Latest development Open development history Security researchers discover stolen FortiGate and SSL VPN credentials database Security researchers discovered a database containing around 75,000 credentials stolen from FortiGate firewall and SSL VPN customers, including usernames, email addresses and plaintext passwords tied to organizations such as Oracle, Spotify, Toyota and AT&T. The exposed logins were said to affect customers in 194 countries and over 21,000 unique domains, creating account-takeover risk for any organization listed in the dataset.
-
NCSC issues FortiBleed guidance for Fortinet customers
The UK’s National Cyber Security Centre issued guidance for Fortinet customers affected by the credential theft campaign, recommending Hudson Rock’s or SOCRadar’s FortiBleed checker tools and checks for indicators of compromise such as unauthorized account creation and unexpected log activity. The guidance was aimed at organizations whose FortiGate and SSL VPN credentials may have been exposed.
Attackers exposed a **FortiBleed** dataset containing around **75,000 stolen credentials** tied to **FortiGate firewall and SSL VPN** customers. The records include usernames, email addresses, and plaintext passwords, creating immediate account-takeover and follow-on access risk for affected organizations. Available reporting associates the exposed logins with customers in **194 countries** and **over 21,000 unique domains**, indicating broad international reach.
Named organizations in the exposed data include Oracle, Spotify, Toyota, and AT&T, but the full victim list and the rate of successful misuse are not publicly confirmed. The initial intrusion path into Fortinet environments remains unconfirmed in available material, with discussion ranging from older product weaknesses to a possible zero-day. The described attack flow indicates that configuration data was stolen first and that the passwords in the dataset were then available for brute-force or credential-reuse activity against internet-facing systems.
The UK **NCSC** has advised potentially affected customers to use **FortiBleed** exposure-checking tools and to review for indicators such as unauthorized account creation and unexpected log activity. Immediate defensive work centers on identifying exposed accounts, rotating credentials, reviewing administrative changes, and checking remote-access infrastructure for signs of secondary compromise. Available evidence does not yet establish the exact root cause, the total number of compromised organizations, or how many exposed credentials have already been used successfully.
Signals
Impact signals
Affected impact
Data exposure
Tooling context
1 toolsMember happenings
Data Leak
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Type
Email Addresses
Data Type
Usernames
Data Status
Fully Leaked
Data Leak
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Type
Email Addresses
Data Type
Usernames
Data Status
Fully Leaked