Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Campaign

FortiBleed credential-harvesting operation expands from FortiGate to broader exposed services

Updated 23.06.2026 21:20
Case score 75
Case score 75 Members 2 Latest activity 23.06.2026 21:20
Active exploitation
Members 2 First seen 22.06.2026 23:01 Last seen 23.06.2026 21:20 Updated 23.06.2026 21:20

Overview

**FortiBleed** activity has grown from a **Fortinet FortiGate** credential-harvesting campaign into a broader brute-force push against other internet-facing authentication services, including Synology, Sophos, RDWeb, Citrix SSL-VPN, and MS-SQL. The operators are described as an initial access broker and remain active, using stolen and cracked credentials to move from exposed edge access toward downstream internal systems. Available figures place the FortiGate side of the operation at more than **430,000 firewalls** in scope and over **110 million credentials** identified, and the activity has already progressed to confirmed data theft from a **NATO-aligned defense contractor**. No CVE or patch-led fix is established in available material, so response pressure is centered on exposed-login hardening, credential rotation, and hunting for FortiGate packet-sniffing abuse.

Signals

5 derived
Impact signals
Exploitation
Exploitation Active exploitation
Affected impact
Affected service
Victims/regions
Victim region United States
Status
Campaign status Active
Threat context
Tooling

Malware context

0 families · 13 tools
Tools
CyberStrike CyberStrikeAI forticheck FortigateSniffer FortiProbe-fast GeoSplit HASHBOT Hashmat +5

Member happenings

2 related
Exploitation Wave FortiBleed multi-vendor brute-force wave
Updated 23.06.2026 21:20 Lead Contribution 75
Exploitation Active Exploitation

A **multi-vendor brute-force wave** tied to **FortiBleed** is hitting **Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL** targets, expanding the risk from one firewall-focused operation into a broader exposed-services campaign.

Campaign Initial access broker (IAB) campaign expands across multiple victims
Updated 22.06.2026 23:01 Scoring Support
Objective Access Brokerage Campaign Active

The **FortiBleed** campaign is a live **credential-harvesting** activity targeting **Fortinet FortiGate** devices worldwide. It has been active since at least **February 2026** and is now reported to have extended from exposed firewall compromise into direct data theft, including **DFS backup data** from a **NATO-aligned defense contractor** on **June 15**. The operator is described as an **initial access broker (IAB)** using **FortigateSniffer** and related tooling to capture authentication traffic, crack credentials, and enable broader network access.