CISA FortiBleed mitigation guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a large-scale credential theft campaign. Reported figures now place the verified credential set at 86,644 confirmed working credentials across 194 countries, with researchers also citing at least four organizations fully compromised. CISA’s actions center on ending active sessions, resetting credentials, enabling phishing-resistant MFA, reviewing logs, and restricting management access to reduce account abuse.
Related Happenings
BEC defensive guidance for exposed-credential and account-misuse risk
Defensive Guidance
H score14
First: 30.06.2026 17:00
Last: 30.06.2026 17:00
Sources 1
About this happening:
BEC defenders are being pushed toward tighter training and account-response controls as operators combine AI-generated business correspondence, call-center press...
BEC defensive guidance for exposed-credential and account-misuse risk
Defensive GuidanceAbout this happening: BEC defenders are being pushed toward tighter training and account-response controls as operators combine AI-generated business correspondence, call-center press...
Service desk social engineering defenses tighten identity verification for password resets and MFA changes
Defensive Guidance
H score17
First: 24.06.2026 17:02
Last: 24.06.2026 17:02
Sources 1
About this happening:
Service desk identity verification is being tightened against social engineering attacks, reducing impersonation-driven account takeover and unauthorized access across cor...
Service desk social engineering defenses tighten identity verification for password resets and MFA changes
Defensive GuidanceAbout this happening: Service desk identity verification is being tightened against social engineering attacks, reducing impersonation-driven account takeover and unauthorized access across cor...
Initial access broker (IAB) campaign expands across multiple victims
Campaign
H score89
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Initial access broker (IAB) campaign expands across multiple victims
CampaignAbout this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Latest development: 23.06.2026 13:30
On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware Activity
H score72
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware ActivityAbout this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Leak
H score93
First: 22.06.2026 11:30
Last: 22.06.2026 11:30
Sources 1
About this happening:
The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data LeakAbout this happening: The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
Timeline
-
19.06.2026 09:47 4 articles · 26d ago
CISA urges Fortinet customers to secure devices after FortiBleed leak
Mitigation Patch UpdateCISA told affected FortiGate appliance owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials using PBKDF2, and restrict public internet access to firewall management interfaces after the FortiBleed exposure of about 74,000 Fortinet credentials.
Show sources
- CISA warns Fortinet users to secure devices after FortiBleed leak — www.bleepingcomputer.com — 19.06.2026 09:47
- CISA warns Fortinet users to secure devices after FortiBleed leak — www.bleepingcomputer.com — 19.06.2026 09:47
- FortiBleed: 86,000 Fortinet Device Credentials Compromised — www.securityweek.com — 19.06.2026 13:48
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices — thehackernews.com — 19.06.2026 17:00