Initial access broker (IAB) campaign expands across multiple victims
Campaign
Summary
Hide ▲
Show ▼
The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 and is now reported to have extended from exposed firewall compromise into direct data theft, including DFS backup data from a NATO-aligned defense contractor on June 15. The operator is described as an initial access broker (IAB) using FortigateSniffer and related tooling to capture authentication traffic, crack credentials, and enable broader network access.
Cases
Related Happenings
FortiBleed multi-vendor brute-force wave
Exploitation Wave
H score75
First: 23.06.2026 21:20
Last: 23.06.2026 21:20
Sources 1
How related:
Perhaps the most interesting finding is that FortiBleed appears to be part of a broader, multi-vendor initial access operation that's orchestrated to not only target Fortinet devices, but also breach Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers using automated brute-forcing since February 28, 2026.
About this happening:
A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...
FortiBleed multi-vendor brute-force wave
Exploitation WaveHow related: Perhaps the most interesting finding is that FortiBleed appears to be part of a broader, multi-vendor initial access operation that's orchestrated to not only target Fortinet devices, but also breach Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers using automated brute-forcing since February 28, 2026.
About this happening: A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware Activity
H score72
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
How related:
FortigateSniffer, the most important tool in the operation, abuses the legitimate FortiOS diagnostic command to passively capture authentication traffic across 24 protocols.
About this happening:
FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware ActivityHow related: FortigateSniffer, the most important tool in the operation, abuses the legitimate FortiOS diagnostic command to passively capture authentication traffic across 24 protocols.
About this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
CISA warning on FortiBleed for FortiGate customers
Public Sector Action
H score89
First: 19.06.2026 17:00
Last: 19.06.2026 17:00
Sources 1
About this happening:
CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA warning on FortiBleed for FortiGate customers
Public Sector ActionAbout this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
FortiBleed Fortinet credential-theft campaign
Campaign
H score89
First: 19.06.2026 13:48
Last: 19.06.2026 13:48
Sources 1
About this happening:
The FortiBleed campaign is a global Fortinet credential-theft effort affecting FortiGate firewall and SSL VPN customers. On June 19, 2026, CISA urged harde...
FortiBleed Fortinet credential-theft campaign
CampaignAbout this happening: The FortiBleed campaign is a global Fortinet credential-theft effort affecting FortiGate firewall and SSL VPN customers. On June 19, 2026, CISA urged harde...
Latest development: 22.06.2026 11:30
The UK’s National Cyber Security Centre issued guidance for Fortinet customers impacted by FortiBleed after the campaign exposed around 75,000 credentials from FortiGate firewall and SSL VPN customers. The NCSC urged affected organizations to use Hudson Rock’s or SOCRadar’s FortiBleed checker tools and then review indicators of compromise such as unauthorized account creation and unexpected activity in log files.
CISA FortiBleed mitigation guidance
Advisory/Mitigation
H score67
First: 19.06.2026 09:47
Last: 19.06.2026 09:47
Sources 1
About this happening:
CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...
CISA FortiBleed mitigation guidance
Advisory/MitigationAbout this happening: CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...
Timeline
-
23.06.2026 13:30 1 articles · 22d ago
FortiBleed operators exfiltrate DFS backup data from a NATO-aligned defense contractor
Victim Impact UpdateOn June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.
Show sources
- Russian Initial Access Broker Behind FortiBleed Campaign — www.securityweek.com — 23.06.2026 13:30
-
22.06.2026 23:01 3 articles · 23d ago
FortiBleed campaign uses a custom FortiGate sniffer to steal credentials
Campaign Scope UpdateSOCRadar says the FortiBleed campaign targeting Fortinet FortiGate devices used a Golang-based tool called FortigateSniffer to abuse FortiOS's `diagnose sniffer packet` feature, capture authentication traffic on compromised firewalls, and extract credentials, password hashes, Kerberos tickets, NTLM material, email credentials, and database credentials. The operation was described as targeting more than 430,000 FortiGate firewalls worldwide and as having been active since at least February 2026.
Show sources
- FortiBleed campaign used custom FortiGate sniffer to steal credentials — www.bleepingcomputer.com — 22.06.2026 23:01
- FortiBleed campaign used custom FortiGate sniffer to steal credentials — www.bleepingcomputer.com — 22.06.2026 23:01
- FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation — thehackernews.com — 23.06.2026 21:20