FortiBleed Campaign: Mass FortiGate SSL VPN / Admin Credential Exposure Affecting ~73,932 Fortinet Firewalls Across 194 Countries — Threadlinqs Intelligence
As of 2026-06-19, FortiBleed Campaign: Mass FortiGate SSL VPN / Admin Credential Exposure Affecting ~73,932 Fortinet Firewalls Across 194 Countries is a critical-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0868 · Severity: CRITICAL · Status: ACTIVE · Category: DATA_BREACH
A Russian-speaking, multi-operator threat group exposed valid administrative and SSL VPN credentials for approximately 73,932 internet-facing FortiGate firewalls in 194 countries, harvested via
FortiBleed is a mass credential-exposure campaign publicly disclosed on 2026-06-13 by security researcher Bob (Volodymyr) Diachenko and independently validated by Kevin Beaumont and Hudson Rock. An exposed actor-controlled server was found to contain a dataset of validated administrator and SSL VPN credentials — usernames, email addresses, and plaintext passwords — for 73,932 FortiGate firewall URLs spanning 21,600+ domains across 194 countries, an estimated half of all internet-facing Fortinet firewalls. Named victim organizations in the dataset reportedly include Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Lenovo, PwC, Accenture, and Oracle, alongside government agencies and critical-infrastructure operators.
The operators ran credential attacks at industrial scale: roughly 1.16 billion credential attempts against 320,777 FortiGate targets and a parallel ~2.1 billion attempts against 163,650 Microsoft SQL Server systems. Rather than relying on a single new vulnerability, the campaign aggregated and revalidated credentials from multiple vectors: online brute-forcing/password-spraying, interception of FortiGate SSL VPN authentication hashes, and offline cracking of those hashes using Hashcat orchestrated across a 45-GPU cluster via Hashtopolis. The dataset also incorporates lineage from prior Fortinet credential leaks — the 2021 dump of ~500,000 FortiGate VPN accounts harvested via the CVE-2018-13379 SSL VPN path-traversal flaw, and the January 2025 Belsen Group release of ~15,000 FortiGate device configurations — though FortiBleed is a distinct, larger, and more recent corpus.
Validated credentials were used to access internal networks and Active Directory environments, enabling discovery, lateral movement, collection from network shares, and exfiltration. The actor catalogued credentials by country, sector, and organization revenue, and showed suspected espionage objectives: a Turkish NATO defense contractor reportedly had classified documents exfiltrated, and targeting was observed against organizations in Japan, Taiwan, Vietnam, Iraq, and Türkiye. Operational artifacts left exposed included credential-capture logs (e.g. fg_capture.log), Hashcat/Hashtopolis orchestration files, Active Directory enumeration scripts, password-spraying tooling, and SMB/DFS collection utilities. A single observed indicator, 85.11.187.8 (AS211486), showed HTTP activity on port 9999 on 2026-06-07 and follow-on SSH/VNC/RDP activity on 2026-06-14/15. BeaconBeagle returned no C2 beacon or config correlation for this IP at time of research. Fortinet's remediation path centers on rotating all admin/VPN credentials, enforcing MFA, removing management-interface internet exposure, and upgrading FortiOS to versions implementing PBKDF2 password hashing (7.2.11+, 7.4.8+, 7.6.1+) with forced administrator re-authentication post-upgrade.
Weaknesses (CWE)
CWE-522, CWE-256, CWE-307, CWE-798, CWE-916
Target sectors: government, telecommunications, financial services, healthcare, manufacturing, critical infrastructure, defense, IT services, education, energy
Target regions: Global (194 countries), North America, Europe, Asia, Middle East, Latin America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
DATA_BREACH, CRITICAL, threat intelligence, cybersecurity, CVE-2018-13379, CVE-2022-40684, T1595, T1592, T1589, T1588, T1586, T1583, T1078, T1190, T1133, T1110