FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 Countries — Threadlinqs Intelligence
As of 2026-06-19, FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 Countries is a high-severity threat intel threat attributed to FortiBleed operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-0882 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: FortiBleed operators · FINANCIAL
FortiBleed is an active campaign by a multi-operator Russian-speaking cybercriminal group that compromised 73,932 unique internet-facing Fortinet FortiGate firewall URLs (roughly half of the
FortiBleed is a credential-driven mass-compromise campaign disclosed in June 2026 after security researcher Volodymyr 'Bob' Diachenko discovered an exposed dataset and the attackers' own open directory of tooling, scripts, connection strings, logs, and analytics. Hudson Rock and Kevin Beaumont independently validated portions of the dataset. The operation is attributed with moderate confidence to a Russian-speaking, multi-operator cybercriminal collective coordinating via Telegram.
The attackers systematically scanned the internet for Fortinet FortiGate devices exposing SSL VPN portals or management interfaces, then tested credentials at industrial scale: approximately 1.16 billion credential attempts against 320,777 FortiGate targets and approximately 2.1 billion brute-force attempts against 163,650 Microsoft SQL Server systems. Rather than cracking strong passwords directly, the operators primarily matched live targets against vast repositories of historical credentials previously stolen by infostealer malware, which allowed even highly complex 20-character passwords to be 'compromised' because the plaintext had already been exfiltrated from an endpoint. Where hashes were obtained — including intercepted SSL VPN authentication hashes and credentials extracted from device configuration files — the group ran offline cracking on a dedicated 45-GPU cluster orchestrated with Hashtopolis and hashcat. Older FortiGate devices using salted SHA-256 hashing (pre-2025, before Fortinet's early-2025 PBKDF2 hardening) were especially vulnerable to offline cracking.
The end state was administrative access to 73,932 unique FortiGate URLs spanning 21,632 distinct domains in 194 countries. The most affected countries were India (9,629 devices), the United States (6,352), Taiwan (3,637), Mexico (3,197), and Turkey (3,032). After gaining firewall access, the operators pivoted into internal networks, ran Active Directory enumeration and full-domain audits, sprayed credentials, and exfiltrated data from network shares (DFS backups, SMB). Confirmed or reported victims include a Turkish NATO defense contractor (from which classified documents were allegedly exfiltrated) and entries for major enterprises such as Foxconn, Samsung, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, Siemens, Lenovo, Oracle, Chevron, PwC, and Accenture. The campaign is distinct from the 2025 Belsen Group Fortinet leak (~15,000 devices). Command-and-control / credential-harvesting infrastructure was observed at 85.11.187.8 (AS211486, 85.11.187.0/24), with HTTP activity on port 9999 on 2026-06-07 and SSH/VNC/RDP services active on 2026-06-14 through 2026-06-15.
Weaknesses (CWE)
CWE-307, CWE-521, CWE-798, CWE-916, CWE-1392
Target sectors: it-services, telecommunications, financial-services, government, defense, manufacturing, automotive, energy, healthcare, education, construction-materials
Target regions: Asia, North America, Europe, Middle East, Latin America, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1595, T1595.002, T1589.001, T1583, T1588.002, T1586, T1190, T1133, T1078, T1110.001