FortiBleed Fortinet credential-theft campaign
Campaign
Summary
Hide ▲
Show ▼
The FortiBleed campaign is a global Fortinet credential-theft effort affecting FortiGate firewall and SSL VPN customers. On June 19, 2026, CISA urged hardening after reporting 86,644 confirmed working credentials tied to 194 countries and advising actions such as session termination, credential resets, PBKDF2 for admin logins, log review, phishing-resistant MFA, and tighter management access. On June 22, the UK’s NCSC issued follow-up guidance after reporting around 75,000 credentials exposed and telling customers to use Hudson Rock or SOCRadar checker tools and review for suspicious account creation and log activity.
Related Happenings
Initial access broker (IAB) campaign expands across multiple victims
Campaign
H score89
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Initial access broker (IAB) campaign expands across multiple victims
CampaignAbout this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Latest development: 23.06.2026 13:30
On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Leak
H score93
First: 22.06.2026 11:30
Last: 22.06.2026 11:30
Sources 1
How related:
A database of around 75,000 credentials stolen from FortiGate firewall and SSL VPN customers was discovered by security researchers last week.
About this happening:
The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data LeakHow related: A database of around 75,000 credentials stolen from FortiGate firewall and SSL VPN customers was discovered by security researchers last week.
About this happening: The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
CISA warning on FortiBleed for FortiGate customers
Public Sector Action
H score89
First: 19.06.2026 17:00
Last: 19.06.2026 17:00
Sources 1
How related:
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices.
About this happening:
CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA warning on FortiBleed for FortiGate customers
Public Sector ActionHow related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices.
About this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA FortiBleed mitigation guidance
Advisory/Mitigation
H score67
First: 19.06.2026 09:47
Last: 19.06.2026 09:47
Sources 1
How related:
On Thursday, CISA issued an alert on FortiBleed, urging Fortinet customers to take hardening actions: terminate active sessions and reset credentials, ensure they use Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store admin logins, review logs to identify suspicious activity, enable phishing-resistant MFA, and lock down management access to reduce the attack surface.
About this happening:
CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...
CISA FortiBleed mitigation guidance
Advisory/MitigationHow related: On Thursday, CISA issued an alert on FortiBleed, urging Fortinet customers to take hardening actions: terminate active sessions and reset credentials, ensure they use Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store admin logins, review logs to identify suspicious activity, enable phishing-resistant MFA, and lock down management access to reduce the attack surface.
About this happening: CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...
FortiBleed Fortinet/FortiGate VPN credential leak
Data Leak
H score80
First: 17.06.2026 18:12
Last: 17.06.2026 18:12
Sources 1
How related:
“Discovered in June 2026, the operation has produced a verified database of over 86,644 confirmed working credentials across 194 countries, all collected from internet-facing Fortinet infrastructure,” the company says.
About this happening:
FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
FortiBleed Fortinet/FortiGate VPN credential leak
Data LeakHow related: “Discovered in June 2026, the operation has produced a verified database of over 86,644 confirmed working credentials across 194 countries, all collected from internet-facing Fortinet infrastructure,” the company says.
About this happening: FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
Latest development: 19.06.2026 09:47
CISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.
Timeline
-
22.06.2026 11:30 1 articles · 23d ago
NCSC issues FortiBleed guidance for Fortinet customers
Mitigation Patch UpdateThe UK’s National Cyber Security Centre issued guidance for Fortinet customers impacted by FortiBleed after the campaign exposed around 75,000 credentials from FortiGate firewall and SSL VPN customers. The NCSC urged affected organizations to use Hudson Rock’s or SOCRadar’s FortiBleed checker tools and then review indicators of compromise such as unauthorized account creation and unexpected activity in log files.
Show sources
- NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout — www.infosecurity-magazine.com — 22.06.2026 11:30
-
19.06.2026 13:48 3 articles · 26d ago
CISA urges hardening after FortiBleed exposes Fortinet credentials
Initial DisclosureCISA urged organizations to harden internet-accessible Fortinet devices after the FortiBleed credential-theft campaign was linked to more than 86,000 firewalls and VPNs. Researchers described 86,644 confirmed working credentials collected from Fortinet infrastructure across 194 countries, with guidance to terminate active sessions, reset credentials, use PBKDF2 for admin logins, review logs, enable phishing-resistant MFA, and lock down management access.
Show sources
- FortiBleed: 86,000 Fortinet Device Credentials Compromised — www.securityweek.com — 19.06.2026 13:48
- FortiBleed: 86,000 Fortinet Device Credentials Compromised — www.securityweek.com — 19.06.2026 13:48
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices — thehackernews.com — 19.06.2026 17:00