FortiBleed Fortinet/FortiGate VPN credential leak
Data Leak
Summary
Hide ▲
Show ▼
FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from internet-facing Fortinet infrastructure across 194 countries. CISA urged customers to harden FortiGate devices by terminating sessions, resetting credentials, enabling phishing-resistant MFA, reviewing logs, and restricting management access. Reporting links the exposure to a Russian-speaking threat actor using SSL VPN authentication interception, hash cracking, and Active Directory pivoting, with at least four organizations fully compromised and broad impact across government and critical infrastructure.
Related Happenings
Initial access broker (IAB) campaign expands across multiple victims
Campaign
H score89
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Initial access broker (IAB) campaign expands across multiple victims
CampaignAbout this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Latest development: 23.06.2026 13:30
On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware Activity
H score72
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware ActivityAbout this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Leak
H score93
First: 22.06.2026 11:30
Last: 22.06.2026 11:30
Sources 1
About this happening:
The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data LeakAbout this happening: The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
CISA warning on FortiBleed for FortiGate customers
Public Sector Action
H score89
First: 19.06.2026 17:00
Last: 19.06.2026 17:00
Sources 1
About this happening:
CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA warning on FortiBleed for FortiGate customers
Public Sector ActionAbout this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
FortiBleed Fortinet credential-theft campaign
Campaign
H score89
First: 19.06.2026 13:48
Last: 19.06.2026 13:48
Sources 1
How related:
“Discovered in June 2026, the operation has produced a verified database of over 86,644 confirmed working credentials across 194 countries, all collected from internet-facing Fortinet infrastructure,” the company says.
About this happening:
The FortiBleed campaign is a global Fortinet credential-theft effort affecting FortiGate firewall and SSL VPN customers. On June 19, 2026, CISA urged harde...
FortiBleed Fortinet credential-theft campaign
CampaignHow related: “Discovered in June 2026, the operation has produced a verified database of over 86,644 confirmed working credentials across 194 countries, all collected from internet-facing Fortinet infrastructure,” the company says.
About this happening: The FortiBleed campaign is a global Fortinet credential-theft effort affecting FortiGate firewall and SSL VPN customers. On June 19, 2026, CISA urged harde...
Latest development: 22.06.2026 11:30
The UK’s National Cyber Security Centre issued guidance for Fortinet customers impacted by FortiBleed after the campaign exposed around 75,000 credentials from FortiGate firewall and SSL VPN customers. The NCSC urged affected organizations to use Hudson Rock’s or SOCRadar’s FortiBleed checker tools and then review indicators of compromise such as unauthorized account creation and unexpected activity in log files.
Timeline
-
19.06.2026 09:47 1 articles · 26d ago
CISA urges Fortinet customers to secure FortiGate devices after FortiBleed leak
Mitigation Patch UpdateCISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.
Show sources
- CISA warns Fortinet users to secure devices after FortiBleed leak — www.bleepingcomputer.com — 19.06.2026 09:47
-
17.06.2026 18:12 3 articles · 28d ago
FortiBleed exposes Fortinet and FortiGate VPN credentials worldwide
Initial DisclosureBob Diachenko found a server containing apparent Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords, and the FortiBleed dataset is described as exposing Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. Hudson Rock later said the collection spans 194 countries and roughly 21,632 unique domains, while Kevin Beaumont said some of the credentials are authentic and that the data appears to have come from exported Fortinet configurations.
Show sources
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. — www.bleepingcomputer.com — 17.06.2026 18:12
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. — www.bleepingcomputer.com — 17.06.2026 18:12
- FortiBleed: 86,000 Fortinet Device Credentials Compromised — www.securityweek.com — 19.06.2026 13:48