FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways
FortiBleed: Russian-Speaking Credential-Harvesting Campaign (TL-2026-0895), also tracked as FortiBleed, is a high-severity tracked intrusion set, first published 2026-06-21. It is attributed to INC Ransom - G1032 (Russia) with medium confidence, affects Fortinet FortiGate / FortiOS, maps to 25 MITRE ATT&CK techniques (T1018, T1021, T1039), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-0895
- Threat ID
- TL-2026-0895
- Also known as
- FortiBleed
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-06-21
- Last reviewed
- 2026-06-21
- Attribution
- INC Ransom - G1032
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government, defense, financial, technology, telecommunications, managed-service-providers, critical-infrastructure
- Target regions
- Asia, North America, Europe, Middle East, Latin America, Global (194 countries)
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in FortiBleed: Russian-Speaking Credential-Harvesting Campaign
Malware and tooling: Hashcat, Hashtopolis 0.14.3, Telegram bot tasking
FortiBleed is an active, large-scale credential-harvesting campaign in which Russian-speaking threat actors compromised internet-facing FortiGate firewalls and SSL VPN gateways across 194 countries by reusing leaked credentials, brute-forcing weak/MFA-less accounts, and offline-cracking legacy salted-SHA256 FortiOS hashes on a GPU cluster. Public reporting cites 73,932 affected firewall URLs (~50% of the internet-facing fleet) and 30,791 verified working credentials. This is not a new zero-day; it weaponizes weak password hygiene, absent MFA, and credentials exposed in prior Fortinet incidents (FG-IR-26-060, FG-IR-25-647).
How FortiBleed: Russian-Speaking Credential-Harvesting Campaign works
FortiBleed is a credential-harvesting and credential-validation campaign that targets internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways at global scale. Rather than exploiting a single new vulnerability, the operators chained together previously leaked Fortinet credentials, aggressive automated brute-force / credential-stuffing, and large-scale offline hash cracking against the legacy salted-SHA256 administrator-credential format used by older FortiOS builds.
Researchers (SOCRadar, Arctic Wolf, Recorded Future, CSO Online, SpyCloud, CloudSEK, Field Effect) describe an attacker-controlled open directory and orchestration stack left exposed on the internet. The operators ran a Hashtopolis 0.14.3 instance (reachable at 85.11.187.8:8443) coordinating a roughly 45-GPU cracking cluster (with ~36 Vast.ai rented GPU workers) using Hashcat to recover plaintext administrator and SSL VPN passwords from captured FortiOS config hashes (legacy salted-SHA256, PBKDF2, and krb5pa$18200 Kerberos formats). Telemetry attributed to the campaign includes roughly 1.16 billion credential attempts against 320,777 FortiGate targets and roughly 2.1 billion attempts against 163,650 MSSQL systems, indicating a broad automated credential-validation pipeline beyond Fortinet alone.
The operators maintained databases of validated credentials organized by country, sector, and organization revenue, and an exposed dataset attributed 21,632 entries (largely registration/realm metadata, with only a small fraction confirming real internal compromise — meaning headline breach counts are likely inflated). After authenticating to a FortiGate, attackers deployed passive network sniffers (logging to fg_capture.log) to harvest additional plaintext credentials transiting the perimeter device, created rogue administrator accounts (forticloud, fortiuser, fortinet-support, fortinet-tech-support), modified device configuration, and pivoted toward Active Directory / LDAP-integrated internal environments using enumeration (ad_enum.py, ad_full_audit.py), password spraying (spray_admin.sh, spray_da.py), and SMB/DFS collection-and-exfiltration tooling (backup_dfs.py, spider.py, smb_test.py). At least one working SSL VPN profile into a victim network (vpn5.conf) was found in the exposed directory. Confirmed victims span Japan, Taiwan, Vietnam, Iraq, and Türkiye, with reporting that a NATO defense contractor was targeted and documents allegedly exfiltrated; India, the United States, and Mexico held the largest concentrations of exposed credentials.
FortiOS builds prior to 7.2.11, 7.4.8, and 7.6.1 stored administrator credentials as salted SHA-256, which is feasible to crack offline; later builds (7.4/7.6/8.0 lines, beginning 7.2.11/7.4.8/7.6.1) introduce PBKDF2 hashing. Critically, legacy SHA-256 hashes persist in 'old-password' fields after an upgrade until each administrator logs in, extending the exposure window. Remediation requires terminating all admin/VPN sessions and rotating every credential, enforcing MFA, upgrading FortiOS, enabling 'set login-lockout-upon-weaker-encryption', auditing configurations for rogue accounts and unauthorized changes, restricting management-interface exposure, and reviewing logs and domain-controller telemetry for lateral-movement anomalies.
MITRE ATT&CK techniques used in TL-2026-0895
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1087 Account Discovery
Lateral Movement
Collection
T1039 Data from Network Shared Drive; T1074 Data Staged
Credential Access
T1040 Network Sniffing; T1110 Brute Force; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Defense Evasion
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Persistence
T1098 Account Manipulation; T1136 Create Account
Resource Development
T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1588 Obtain Capabilities
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning
Affected products and versions in FortiBleed: Russian-Speaking Credential-Harvesting Campaign
- Fortinet — FortiGate / FortiOS
Vulnerable versions: FortiOS prior to 7.2.11; FortiOS prior to 7.4.8; FortiOS prior to 7.6.1 (legacy salted-SHA256 administrator credential hashing)
Fixed in: FortiOS 7.2.11+; FortiOS 7.4.8+; FortiOS 7.6.1+; 7.4 / 7.6 / 8.0 latest releases (PBKDF2 hashing) - Fortinet — FortiGate SSL VPN gateway
Vulnerable versions: Internet-exposed SSL VPN on FortiOS builds without MFA and with legacy hashing
Fixed in: PBKDF2-supporting FortiOS builds with MFA enforced
Remediation for FortiBleed: Russian-Speaking Credential-Harvesting Campaign
Patches
- Upgrade FortiOS to a PBKDF2-supporting release (7.2.11+, 7.4.8+, 7.6.1+, or the 7.4 / 7.6 / 8.0 latest lines)
Immediate actions
- Terminate all administrator and SSL VPN sessions and force-reset every administrator and VPN credential on internet-facing FortiGate devices
- Audit FortiGate local admin accounts for rogue usernames (forticloud, fortiuser, fortinet-support, fortinet-tech-support) and remove any unrecognized accounts
- Review device configuration for unauthorized changes, new admin profiles, and altered trusted-host/management-access settings
- Block attacker infrastructure (85.11.187.8, 85.11.187.28, 193.8.187.2, 185.229.26.83, 213.169.49.142, 85.11.187.0/24) at the perimeter
Workarounds
- Run 'set login-lockout-upon-weaker-encryption' to remove legacy weaker-encryption password settings and clear residual salted-SHA256 'old-password' hashes
- Force every administrator to log in after upgrade so legacy SHA-256 hashes in 'old-password' fields are replaced with PBKDF2
Longer-term hardening
- Enforce multi-factor authentication on all administrator and SSL VPN accounts
- Restrict management and SSL VPN interfaces to trusted source hosts; remove direct internet exposure where possible
- Audit Active Directory / LDAP integrations and domain controllers for enumeration, password spraying, and anomalous authentications
- Establish known-good configuration baselines and continuously diff FortiGate configs against them
Weaknesses (CWE) in FortiBleed: Russian-Speaking Credential-Harvesting Campaign
CWE-916, CWE-522, CWE-307, CWE-798, CWE-1392, CWE-256
Timeline of FortiBleed: Russian-Speaking Credential-Harvesting Campaign
- Earliest timestamped FortiGate credential-capture cycle observed (10:52 AM EDT); attackers also created a Cursor AI code editor account the same day.
- HTTP activity observed on port 9999 of attacker infrastructure 85.11.187.8; Hashtopolis 0.14.3 coordination instance reachable at 85.11.187.8:8443.
- Public disclosure of the FortiBleed dataset by researcher Volodymyr Diachenko; ~73,932 FortiGate firewall URLs reported exposed across 194 countries.
- Follow-on intrusion activity observed June 14-15 across SSH, VNC, and RDP from attacker infrastructure.
- Arctic Wolf and Field Effect publish FortiBleed bulletins; SOCRadar reports 30,791 verified working credentials and Russian-speaking attribution.
- Recorded Future, CSO Online, SpyCloud, CloudSEK and TechTimes detail attacker open directory, 45-GPU Hashcat/Hashtopolis cluster, MSSQL targeting, and NATO defense contractor targeting.
- Fortinet PSIRT publishes 'Analysis of Reported Credential Compromise of FortiGate Devices', referencing prior incidents FG-IR-26-060 and FG-IR-25-647 and PBKDF2 remediation guidance.
- Cyber Security News publishes FortiBleed campaign report; threat tracked as TL-2026-0895.
Sources cited for FortiBleed: Russian-Speaking Credential-Harvesting Campaign
- FortiBleed - Credential Harvesting Campaign Targeting FortiGate Devices
- Analysis of Reported Credential Compromise of FortiGate Devices (Fortinet PSIRT Blog)
- Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries (Arctic Wolf)
- FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems (Recorded Future)
- FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide (CSO Online)
- Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind
- Inside the FortiBleed Open Directory (CloudSEK)
- FortiBleed exposes Fortinet credentials at global scale (Field Effect)
- What SpyCloud Found Inside the FortiBleed Threat Actor Infrastructure
- NCSC: Advice following global targeting of Fortinet firewalls and VPN gateways
- Fortinet FortiGate Credential Leak Hits 73,932 Firewalls (TechTimes)
Threats related to FortiBleed: Russian-Speaking Credential-Harvesting Campaign
- FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN Gateways
- FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer Tool
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware
- FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 Protocols
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 Countries
Detection coverage for TL-2026-0895
As of 2026-06-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0895 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0895
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.