Russian-speaking FortiGate and Microsoft SQL Server bruteforce campaign
Campaign
Summary
Hide ▲
Show ▼
A Russian-speaking multi-operator threat group ran a FortiGate and Microsoft SQL Server bruteforce campaign that generated billions of credential attempts, raising the risk of widespread account compromise and internal access. The operation targeted 320,777 FortiGate systems and 163,650 SQL Server systems, and recovered credentials were reportedly used for lateral movement into Active Directory environments. The same activity also involved harvesting and cracking SSL VPN hashes, making it a large-scale access-focused intrusion operation.
Related Happenings
FortiBleed multi-vendor brute-force wave
Exploitation Wave
H score75
First: 23.06.2026 21:20
Last: 23.06.2026 21:20
Sources 1
About this happening:
A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...
FortiBleed multi-vendor brute-force wave
Exploitation WaveAbout this happening: A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...
Initial access broker (IAB) campaign expands across multiple victims
Campaign
H score89
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Initial access broker (IAB) campaign expands across multiple victims
CampaignAbout this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Latest development: 23.06.2026 13:30
On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware Activity
H score72
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware ActivityAbout this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Leak
H score93
First: 22.06.2026 11:30
Last: 22.06.2026 11:30
Sources 1
About this happening:
The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data LeakAbout this happening: The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
FortiBleed Fortinet credential-theft campaign
Campaign
H score89
First: 19.06.2026 13:48
Last: 19.06.2026 13:48
Sources 1
About this happening:
The FortiBleed campaign is a global Fortinet credential-theft effort affecting FortiGate firewall and SSL VPN customers. On June 19, 2026, CISA urged harde...
FortiBleed Fortinet credential-theft campaign
CampaignAbout this happening: The FortiBleed campaign is a global Fortinet credential-theft effort affecting FortiGate firewall and SSL VPN customers. On June 19, 2026, CISA urged harde...
Latest development: 22.06.2026 11:30
The UK’s National Cyber Security Centre issued guidance for Fortinet customers impacted by FortiBleed after the campaign exposed around 75,000 credentials from FortiGate firewall and SSL VPN customers. The NCSC urged affected organizations to use Hudson Rock’s or SOCRadar’s FortiBleed checker tools and then review indicators of compromise such as unauthorized account creation and unexpected activity in log files.
Timeline
-
17.06.2026 18:12 2 articles · 28d ago
FortiBleed leak exposes Fortinet VPN credentials for 73,932 firewall URLs
Initial DisclosureA newly discovered data leak dubbed FortiBleed exposed apparent Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide; Bob Diachenko found a server containing valid-looking Fortinet VPN credentials, and follow-on review indicated the dataset may cover roughly 75,000 Fortinet devices across 194 countries.
Show sources
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. — www.bleepingcomputer.com — 17.06.2026 18:12
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. — www.bleepingcomputer.com — 17.06.2026 18:12