Exploitation Wave
Campaign
FortiBleed credential-harvesting operation expands from FortiGate to broader exposed services
Updated 23.06.2026 21:20
Case score 75
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 75
- Main story score
- 75
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Exploitation Wave Anchors the shift from FortiGate-focused activity into a wider brute-force wave across multiple exposed services. main
- Campaign Provides the FortiGate-centered tradecraft, scale figures, and confirmed escalation to defense-contractor data theft. main
Case score 75
Members 2
Latest activity 23.06.2026 21:20
Active exploitation
Members 2
First seen 22.06.2026 23:01
Last seen 23.06.2026 21:20
Updated 23.06.2026 21:20
Overview
**FortiBleed** activity has grown from a **Fortinet FortiGate** credential-harvesting campaign into a broader brute-force push against other internet-facing authentication services, including Synology, Sophos, RDWeb, Citrix SSL-VPN, and MS-SQL. The operators are described as an initial access broker and remain active, using stolen and cracked credentials to move from exposed edge access toward downstream internal systems.
Available figures place the FortiGate side of the operation at more than **430,000 firewalls** in scope and over **110 million credentials** identified, and the activity has already progressed to confirmed data theft from a **NATO-aligned defense contractor**. No CVE or patch-led fix is established in available material, so response pressure is centered on exposed-login hardening, credential rotation, and hunting for FortiGate packet-sniffing abuse.
Attackers behind **FortiBleed** are running an active credential-harvesting and brute-force operation against internet-facing access points, starting with **Fortinet FortiGate** and expanding to **Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers**. The activity has been active since at least February 2026, and available material describes the operator as an initial access broker focused on collecting and reusing credentials across reachable authentication services. What began as a FortiGate-centered intrusion set has widened into a broader multi-vendor initial-access push rather than staying limited to one firewall platform.
On compromised **FortiGate** devices, the operators use SSH access and a custom Golang tool called **FortigateSniffer** to abuse the **FortiOS diagnose sniffer packet** capability and passively capture authentication traffic. The reported haul includes cleartext credentials, password hashes, Kerberos material, NTLM data, email credentials, database credentials, and large volumes of MySQL and RADIUS authentication data. Available figures place the campaign at more than **430,000 FortiGate firewalls** worldwide, with at least **659 credential-harvesting pipelines** and over **110 million credentials** identified.
The operation has also moved beyond credential collection into confirmed downstream compromise, with operators reportedly cracking Kerberos hashes and exfiltrating DFS backup data from a **NATO-aligned defense contractor** on June 15. No **CVE** or patch-led fix is established in the available material, so immediate response centers on hardening exposed authentication services, reviewing **FortiGate** administrative and SSH access, rotating potentially exposed credentials, and hunting for packet-sniffing abuse and credential reuse.
Signals
5 derivedImpact signals
Exploitation
Exploitation
Active exploitation
Affected impact
Affected service
Victims/regions
Victim region
United States
Status
Campaign status
Active
Threat context
Tooling
Malware context
0 families · 13 toolsTools
CyberStrike
CyberStrikeAI
forticheck
FortigateSniffer
FortiProbe-fast
GeoSplit
HASHBOT
Hashmat
+5
Member happenings
2 related
Exploitation Wave
FortiBleed multi-vendor brute-force wave
Exploitation
Active Exploitation
Exploitation Wave
FortiBleed multi-vendor brute-force wave
Exploitation
Active Exploitation
Campaign
Initial access broker (IAB) campaign expands across multiple victims
Objective
Access Brokerage
Campaign
Active
Campaign
Initial access broker (IAB) campaign expands across multiple victims
Objective
Access Brokerage
Campaign
Active