FortiBleed credential-harvesting operation expands from FortiGate to broader exposed services
Case score 75
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 75
- Main story score
- 75
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Exploitation Wave Anchors the shift from FortiGate-focused activity into a wider brute-force wave across multiple exposed services. main
- Campaign Provides the FortiGate-centered tradecraft, scale figures, and confirmed escalation to defense-contractor data theft. main
Overview
Latest development Open development history SOCRadar details FortiBleed's 110-million-credential harvesting operation SOCRadar discloses that FortiBleed has targeted over 430,000 FortiGate firewalls globally, with attackers launching 659 credential-harvesting pipelines on May 31 and June 15, 2026, extracting over 110 million credentials and focusing on SMBs, the United States, India, and IT services while cracking hashes with Hashmat and Hashtopolis under HASHBOT control.
-
FortiBleed expands into a multi-vendor brute-force wave
The FortiBleed operation broadens into automated brute-forcing against Fortinet devices, Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers, marking a multi-vendor initial access wave that starts on February 28, 2026.
-
FortiBleed campaign uses a custom FortiGate sniffer to steal credentials
SOCRadar says the FortiBleed campaign targeting Fortinet FortiGate devices used a Golang-based tool called FortigateSniffer to abuse FortiOS's `diagnose sniffer packet` feature, capture authentication traffic on compromised firewalls, and extract credentials, password hashes, Kerberos tickets, NTLM material, email credentials, and database credentials. The operation was described as targeting more than 430,000 FortiGate firewalls worldwide and as having been active since at least February 2026.
-
FortiBleed operators exfiltrate DFS backup data from a NATO-aligned defense contractor
On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.