FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries) — Threadlinqs Intelligence
As of 2026-07-22, FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries) is a critical-severity campaign threat attributed to Lynx) (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 78 indicators of compromise.
Threat ID: TL-2026-1232 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: CAMPAIGN
Updated: 2026-07-22 · 4 updates · revalidated 4× · latest source
Attribution: Lynx) · Russia · FINANCIAL
FortiBleed is an active, self-sustaining credential-harvesting campaign against internet-exposed Fortinet FortiGate SSL VPN and management interfaces. Threat actors extract configuration files, crack
FortiBleed is a large-scale, ongoing credential compromise campaign targeting internet-exposed Fortinet FortiGate devices' SSL VPN and administrative management interfaces, reachable on standard (443) and non-standard (4443, 8443, 10443) HTTPS ports. First identified by security researchers in mid-June 2026 (Wiz Threat Center, Arctic Wolf Labs, SOCRadar) and running since at least February 2026, the campaign is not driven by a single zero-day but by systemic weak credential hygiene compounded by a legacy password-storage weakness in FortiOS.
Fortinet introduced PBKDF2-based password hashing for administrator credentials in FortiOS 7.2.11, 7.4.8, and 7.6.1, replacing a legacy SHA-256-based storage mechanism. Critically, when a device is upgraded from an earlier version, existing administrator passwords remain stored as SHA-256 hashes until the corresponding administrator successfully logs in following the upgrade — leaving a large population of upgraded-but-not-re-authenticated devices with crackable legacy hashes. Threat actors have been systematically extracting configuration files from internet-facing FortiGate devices (via exposed management interfaces, prior breach access, or leaked backups) and cracking the stored SHA-256 hashes offline, then combining the results with credentials harvested from earlier Fortinet-related breach dumps and infostealer logs.
The resulting credential database is continuously revalidated against internet-facing FortiGate devices via automated authentication attempts. Once a device is compromised, it is frequently repurposed as a listening post to passively monitor SSL VPN traffic, harvesting additional live credentials that feed back into the scanner — creating a self-sustaining feedback loop that has driven the campaign's scale. Investigators identified a large fraction of compromised accounts as generic administrative or Fortinet built-in system accounts (e.g., 'admin' variants ~21.4%, 'fgts*' system accounts ~6.95%, 'fort*' system accounts ~5.4-6%, 'telm*' ISP-provisioned accounts ~2.36%), and Fortinet's own PSIRT analysis separately flagged suspicious admin account names to monitor for: forticloud, fortiuser, fortinet-support, fortinet-tech-support.
The campaign closely tracks — and in reporting is frequently conflated/overlapped with — active in-the-wild exploitation of a cluster of Fortinet FortiCloud SSO authentication-bypass vulnerabilities: CVE-2025-59718 and CVE-2025-59719 (improper verification of cryptographic signature in FortiCloud SSO SAML handling, CVSS 9.8/9.1 depending on source, disclosed December 2025, added to CISA KEV December 16 2025) and CVE-2026-24858 (authentication bypass allowing a FortiCloud account holder to authenticate to devices registered under other FortiCloud accounts when SSO is enabled, CVSS 9.8, CWE-288, disclosed January 27 2026, added to CISA KEV the same day). Fortinet observed two malicious FortiCloud accounts actively exploiting CVE-2026-24858 in the wild before locking them out on 2026-01-22, and disabled FortiCloud SSO server-side on 2026-01-26. Both advisory families (FG-IR-25-647 and FG-IR-26-060) are explicitly referenced in Fortinet's own PSIRT analysis of the FortiBleed credential compromise as related, actively-exploited authentication weaknesses in the same feature surface (FortiCloud SSO / admin authentication).
Attribution work by SOCRadar (published June 29, 2026) tentatively links the campaign's infrastructure, tooling choices, and victim-selection patterns to the Lynx/INC Ransom group (also tracked as INC Ransomware), a Russian-speaking ransomware-as-a-service operation active since 2023 with a documented focus on NATO member states and adjacent countries. Analysts noted that defense-industry VPN endpoint credentials were recovered from an exposed operator server, and that the operation's server infrastructure (260+ operational servers, 80,000+ unique IPs, 22,405+ unique domains observed) is organized by country, sector, and victim o
Weaknesses (CWE)
CWE-288, CWE-347, CWE-521, CWE-798, CWE-916, CWE-287, CWE-289, CWE-22, CWE-306, CWE-787
Target sectors: government administration, telecoms, health, education, energy, financial services, banking, manufacturing, critical infrastructure, commercial
Target regions: North America, Europe, Worldwide, india, NATO member states
Update History
- 2026-07-22 — FortiGate Zero-Day (CVE-2026-24858) and FortiBleed Credential-Stuffing Campaign Expose Virtual Appliance Blind Spot: What changed No field escalations — severity, exploitability, and status remain CRITICAL/ACTIVE/ACTIVE as already recorded. This update is additive intelligence, not an escalation. New indicators (15) 14 new indicators: specific rogue admin
- 2026-07-18 — FortiBleed: Mass Credential Compromise Across 73,932 FortiGate Firewalls via Chained Fortinet CVEs and Symlink Persistence: What changed No field escalation — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and CVSS (9.8) all already at maximum in the existing record. The update is additive: it extends the vulnerability chain and adds a persistenc
- 2026-07-18 — FortiBleed: Russian IAB SantaAd's Living-off-the-Land Credential-Harvesting Campaign Compromises 430,000+ Fortinet, Sophos, Synology, and MSSQL Systems, Exposing 110M+ Credentials: What changed No field escalations applied. Severity/exploitability/status unchanged (new report's severity_level HIGH is lower than the existing CRITICAL — a downgrade, so not applied per escalation-only rule). New indicators (18) 18 new IO
- 2026-07-18 — FortiBleed Credential Exposure Exploited: Initial Access Broker Dark_Alpha Selling FortiGate Access on Darkforums: What changed Severity HIGH → CRITICAL: the FortiBleed credential exposure is now confirmed to be actively monetized on the Darkforums cybercrime marketplace by initial access broker Dark_Alpha (two bulk listings, 35,000 and 6,355 verified a
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 78 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
CAMPAIGN, CRITICAL, threat intelligence, cybersecurity, CVE-2026-24858, CVE-2025-59718, CVE-2025-59719, CVE-2018-13379, CVE-2022-42475, CVE-2023-27997, CVE-2024-21762, CVE-2024-55591, CVE-2026-25815, CVE-2022-40684, T1589, T1595, T1583, T1588, T1190, T1133, T1078, T1110, T1110, T1110