Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Campaign

FortiBleed credential-harvesting operation expands from FortiGate to broader exposed services

Updated 23.06.2026 21:20
Case score 75
Members 2 First seen 22.06.2026 23:01 Latest activity 23.06.2026 21:20

Overview

**FortiBleed** activity has grown from a **Fortinet FortiGate** credential-harvesting campaign into a broader brute-force push against other internet-facing authentication services, including Synology, Sophos, RDWeb, Citrix SSL-VPN, and MS-SQL. The operators are described as an initial access broker and remain active, using stolen and cracked credentials to move from exposed edge access toward downstream internal systems. Available figures place the FortiGate side of the operation at more than **430,000 firewalls** in scope and over **110 million credentials** identified, and the activity has already progressed to confirmed data theft from a **NATO-aligned defense contractor**. No CVE or patch-led fix is established in available material, so response pressure is centered on exposed-login hardening, credential rotation, and hunting for FortiGate packet-sniffing abuse.
Latest development Open development history 3 earlier developments SOCRadar details FortiBleed's 110-million-credential harvesting operation SOCRadar discloses that FortiBleed has targeted over 430,000 FortiGate firewalls globally, with attackers launching 659 credential-harvesting pipelines on May 31 and June 15, 2026, extracting over 110 million credentials and focusing on SMBs, the United States, India, and IT services while cracking hashes with Hashmat and Hashtopolis under HASHBOT control.
  1. Earlier development

    FortiBleed expands into a multi-vendor brute-force wave

    The FortiBleed operation broadens into automated brute-forcing against Fortinet devices, Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers, marking a multi-vendor initial access wave that starts on February 28, 2026.

  2. Earlier development

    FortiBleed campaign uses a custom FortiGate sniffer to steal credentials

    SOCRadar says the FortiBleed campaign targeting Fortinet FortiGate devices used a Golang-based tool called FortigateSniffer to abuse FortiOS's `diagnose sniffer packet` feature, capture authentication traffic on compromised firewalls, and extract credentials, password hashes, Kerberos tickets, NTLM material, email credentials, and database credentials. The operation was described as targeting more than 430,000 FortiGate firewalls worldwide and as having been active since at least February 2026.

  3. Earlier development

    FortiBleed operators exfiltrate DFS backup data from a NATO-aligned defense contractor

    On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.

Signals

Impact signals
Exploitation
Affected impact
Geographic context
Status
Threat context

Threat actor context

1 listed

Tooling context

13 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Exploitation Wave FortiBleed multi-vendor brute-force wave
Updated 23.06.2026 21:20 Lead Contribution 75
Exploitation Active Exploitation

A **multi-vendor brute-force wave** tied to **FortiBleed** is hitting **Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL** targets, expanding the risk from one firewall-focused operation into a broader exposed-services campaign.

Campaign Initial access broker (IAB) campaign expands across multiple victims
Updated 22.06.2026 23:01 Scoring Support
Objective Access Brokerage Campaign Active

The **FortiBleed** campaign is a live **credential-harvesting** activity targeting **Fortinet FortiGate** devices worldwide. It has been active since at least **February 2026** and is now reported to have extended from exposed firewall compromise into direct data theft, including **DFS backup data** from a **NATO-aligned defense contractor** on **June 15**. The operator is described as an **initial access broker (IAB)** using **FortigateSniffer** and related tooling to capture authentication traffic, crack credentials, and enable broader network access.