Data Leak
FortiBleed Credential Exposure Affecting FortiGate and SSL VPN Accounts
Updated 22.06.2026 11:30
Case score 93
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 93
- Main story score
- 93
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Data Leak Primary incident covering the exposed credential dataset, stated scale, downstream access risk, and immediate defensive guidance. main
Case score 93
Members 1
Latest activity 22.06.2026 11:30
Members 1
First seen 22.06.2026 11:30
Last seen 22.06.2026 11:30
Updated 22.06.2026 11:30
Overview
A **FortiBleed** dataset containing around **75,000 stolen credentials** tied to **FortiGate firewall and SSL VPN** customers has been exposed, putting affected organizations at immediate risk of account takeover and follow-on network access. The leaked records reportedly include usernames, email addresses, and plaintext passwords, and the exposure has been associated with customers in **194 countries** and **over 21,000 unique domains**.
The initial intrusion method has not been confirmed, but the reported sequence points to stolen configuration data followed by credential abuse opportunities against internet-facing systems. The UK **NCSC** has already issued guidance telling affected organizations to check exposure and review for indicators such as unauthorized account creation and unexpected log activity.
Attackers exposed a **FortiBleed** dataset containing around **75,000 stolen credentials** tied to **FortiGate firewall and SSL VPN** customers. The records include usernames, email addresses, and plaintext passwords, creating immediate account-takeover and follow-on access risk for affected organizations. Available reporting associates the exposed logins with customers in **194 countries** and **over 21,000 unique domains**, indicating broad international reach.
Named organizations in the exposed data include Oracle, Spotify, Toyota, and AT&T, but the full victim list and the rate of successful misuse are not publicly confirmed. The initial intrusion path into Fortinet environments remains unconfirmed in available material, with discussion ranging from older product weaknesses to a possible zero-day. The described attack flow indicates that configuration data was stolen first and that the passwords in the dataset were then available for brute-force or credential-reuse activity against internet-facing systems.
The UK **NCSC** has advised potentially affected customers to use **FortiBleed** exposure-checking tools and to review for indicators such as unauthorized account creation and unexpected log activity. Immediate defensive work centers on identifying exposed accounts, rotating credentials, reviewing administrative changes, and checking remote-access infrastructure for signs of secondary compromise. Available evidence does not yet establish the exact root cause, the total number of compromised organizations, or how many exposed credentials have already been used successfully.
Signals
4 derivedImpact signals
Affected impact
Exposed data
Data exposure
Leak status
Fully Leaked
Data
Email Addresses
Data
Usernames
Malware context
0 families · 1 toolsTools
FortiBleed checker tools
Member happenings
1 related
Data Leak
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Type
Email Addresses
Data Type
Usernames
Data Status
Fully Leaked
Data Leak
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Type
Email Addresses
Data Type
Usernames
Data Status
Fully Leaked