FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN Gateways — Threadlinqs Intelligence
As of 2026-06-23, FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN Gateways is a critical-severity data breach threat attributed to a Russia-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-0916 · Severity: CRITICAL · Status: ACTIVE · Category: DATA_BREACH
Attribution: Russia · FINANCIAL
FortiBleed is an active campaign in which a large dataset of valid Fortinet administrative and SSL-VPN credentials — covering ~73,932 FortiGate firewall URLs across 21,600+ domains in 194 countries —
FortiBleed is a credential-exposure and credential-harvesting campaign first publicly disclosed on 2026-06-13 by security researcher Volodymyr 'Bob' Diachenko and corroborated by Kevin Beaumont (DoublePulsar), Hudson Rock, and PwnDefend. The leaked dataset contains valid administrative and SSL-VPN credentials — usernames, email addresses, plaintext passwords, VPN credentials, and administrative access credentials — for approximately 73,932 unique internet-facing FortiGate firewall URLs spanning 21,600+ domains in 194 countries. Independent estimates place the affected population at roughly 50% of all internet-facing Fortinet firewalls (per Shodan polling), with later tallies reporting up to 86,644 devices.
Researchers assessed that the dataset originated from exported FortiGate configuration files rather than intercepted network traffic. FortiGate stores administrator passwords as SHA-256 hashes with a salt — a fast, weak hashing scheme — until an administrator manually logs in after upgrading to firmware that supports PBKDF2 (introduced in early-2025 builds). Attackers cracked these hashes offline using a 45-GPU cluster orchestrated via Hashtopolis/Hashcat, recovering plaintext credentials without needing ongoing access to the targeted devices. According to Diachenko's investigation, the operators conducted roughly 1.16 billion credential attempts against 320,777 FortiGate targets and approximately 2.1 billion credential attempts against 163,650 Microsoft SQL Server (MSSQL) systems. The exposed dataset also included a business-intelligence layer — company industry, revenue, employee count, and formatted broker-style comments — typical of criminal initial-access markets.
The recovered credentials enable attackers to authenticate to FortiGate management portals and SSL-VPN gateways, change security controls, create backdoor administrator accounts, and pivot into internal networks. Attacker tooling discovered in an exposed directory included Hashtopolis orchestration (bot.py, hashpanel.log, setup files), Active Directory enumeration and audit scripts (ad_enum.py, ad_full_audit.py), password-spraying utilities, and SMB/DFS collection scripts with exfiltration capability, alongside log-clearing markers indicating deliberate evidence removal. Attacker infrastructure was tied to 85.11.187.8 within AS211486 (85.11.187.0/24), observed serving HTTP on port 9999 (2026-06-07) and exhibiting SSH/VNC/RDP activity (2026-06-14 to 2026-06-15). Named or reported victims include organizations in Japan, Taiwan, Vietnam, Iraq, and Türkiye — among them a Turkish NATO defense contractor from which classified documents were allegedly exfiltrated — and the dataset references large enterprises across government, telecommunications, financial services, healthcare, manufacturing, and critical infrastructure.
Fortinet PSIRT (advisory published 2026-06-19, referencing prior advisories FG-IR-26-060 and FG-IR-25-647) confirmed the activity is credential reuse from prior incidents combined with brute-force techniques against devices with weak password hygiene and no multi-factor authentication — explicitly not a new vulnerability or zero-day. Because there is no software flaw to patch, remediation depends on credential rotation, MFA, firmware upgrade to versions that store admin credentials with PBKDF2 (7.4 / 7.6 / 8.0), and removal of internet-facing management exposure. Researchers note the underlying pattern echoes the 2019 mass leak of ~500,000 Fortinet SSL-VPN credentials harvested via CVE-2018-13379, and that the original config-file acquisition vector for some devices may trace to known or undisclosed FortiOS vulnerabilities.
Weaknesses (CWE)
CWE-916, CWE-522, CWE-759, CWE-307, CWE-798
Target sectors: government, telecommunications, financial, healthcare, manufacturing, critical infrastructure, defense
Target regions: Global, Asia, Europe, Middle East, North America
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
DATA_BREACH, CRITICAL, threat intelligence, cybersecurity, T1595, T1589, T1583, T1588, T1586, T1078, T1133, T1110, T1110, T1552