Find notable cyber news and cases, enriched with sources, timelines, and signals.

Initial access broker (IAB) campaign expands across multiple victims

Campaign
First reported
Last updated
Happening score
H score 89
3 unique sources, 3 articles

Summary

Hide ▲

The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 and is now reported to have extended from exposed firewall compromise into direct data theft, including DFS backup data from a NATO-aligned defense contractor on June 15. The operator is described as an initial access broker (IAB) using FortigateSniffer and related tooling to capture authentication traffic, crack credentials, and enable broader network access.

Cases

Related Happenings

FortiBleed multi-vendor brute-force wave

Exploitation Wave
H score75 First: 23.06.2026 21:20 Last: 23.06.2026 21:20 Sources 1

How related: Perhaps the most interesting finding is that FortiBleed appears to be part of a broader, multi-vendor initial access operation that's orchestrated to not only target Fortinet devices, but also breach Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers using automated brute-forcing since February 28, 2026.

About this happening: A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...

FortigateSniffer FortiOS packet-sniffer credential-harvesting tool

Malware Activity
H score72 First: 22.06.2026 23:01 Last: 22.06.2026 23:01 Sources 1

How related: FortigateSniffer, the most important tool in the operation, abuses the legitimate FortiOS diagnostic command to passively capture authentication traffic across 24 protocols.

About this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...

CISA warning on FortiBleed for FortiGate customers

Public Sector Action
H score89 First: 19.06.2026 17:00 Last: 19.06.2026 17:00 Sources 1

About this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...

FortiBleed Fortinet credential-theft campaign

Campaign
H score89 First: 19.06.2026 13:48 Last: 19.06.2026 13:48 Sources 1

About this happening: The FortiBleed campaign is a global Fortinet credential-theft effort affecting FortiGate firewall and SSL VPN customers. On June 19, 2026, CISA urged harde...

Latest development: 22.06.2026 11:30

The UK’s National Cyber Security Centre issued guidance for Fortinet customers impacted by FortiBleed after the campaign exposed around 75,000 credentials from FortiGate firewall and SSL VPN customers. The NCSC urged affected organizations to use Hudson Rock’s or SOCRadar’s FortiBleed checker tools and then review indicators of compromise such as unauthorized account creation and unexpected activity in log files.

CISA FortiBleed mitigation guidance

Advisory/Mitigation
H score67 First: 19.06.2026 09:47 Last: 19.06.2026 09:47 Sources 1

About this happening: CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...

Timeline

  1. 23.06.2026 13:30 1 articles · 22d ago

    FortiBleed operators exfiltrate DFS backup data from a NATO-aligned defense contractor

    Victim Impact Update

    On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.

    Show sources
  2. 22.06.2026 23:01 3 articles · 23d ago

    FortiBleed campaign uses a custom FortiGate sniffer to steal credentials

    Campaign Scope Update

    SOCRadar says the FortiBleed campaign targeting Fortinet FortiGate devices used a Golang-based tool called FortigateSniffer to abuse FortiOS's `diagnose sniffer packet` feature, capture authentication traffic on compromised firewalls, and extract credentials, password hashes, Kerberos tickets, NTLM material, email credentials, and database credentials. The operation was described as targeting more than 430,000 FortiGate firewalls worldwide and as having been active since at least February 2026.

    Show sources