FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)
FortiBleed: Mass Credential Compromise Campaign Against (TL-2026-1232), also tracked as FortiBleed, is a critical-severity campaign scored CVSS 9.8, first published 2026-07-11 and last reviewed 2026-08-31. It is attributed to Lynx (Russia) with low confidence, affects Fortinet FortiOS, references 14 CVEs (CVE-2026-24858, CVE-2025-59718, CVE-2025-59719), maps to 63 MITRE ATT&CK techniques (T1003, T1016, T1018), and is covered by 9 detection rules and 89 indicators of compromise.
Key facts for TL-2026-1232
- Threat ID
- TL-2026-1232
- Also known as
- FortiBleed
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- CAMPAIGN
- First published
- 2026-07-11
- Last reviewed
- 2026-08-31
- Attribution
- Lynx
- Attribution confidence
- LOW
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government administration, telecoms, health, education, energy, financial services, banking, manufacturing, critical infrastructure, commercial
- Target regions
- North America, Europe, Worldwide, india, NATO member states
- Detection rules
- 9
- Indicators of compromise
- 89
- Updates
- 2026-08-31 · 5 updates · revalidated 5× · latest source
FortiBleed is an active, self-sustaining credential-harvesting campaign against internet-exposed Fortinet FortiGate SSL VPN and management interfaces. Threat actors extract configuration files, crack legacy SHA-256 admin password hashes, and continuously revalidate a growing database of working credentials — harvesting confirmed working admin credentials for an estimated 86,644 devices across 194 countries (roughly half of all internet-facing Fortinet firewalls). Activity has been tentatively attributed to the Lynx/INC Ransom group and overlaps with active exploitation of Fortinet FortiCloud SSO authentication-bypass vulnerabilities (CVE-2026-24858, CVE-2025-59718, CVE-2025-59719).
How FortiBleed: Mass Credential Compromise Campaign Against works
FortiBleed is a large-scale, ongoing credential compromise campaign targeting internet-exposed Fortinet FortiGate devices' SSL VPN and administrative management interfaces, reachable on standard (443) and non-standard (4443, 8443, 10443) HTTPS ports. First identified by security researchers in mid-June 2026 (Wiz Threat Center, Arctic Wolf Labs, SOCRadar) and running since at least February 2026, the campaign is not driven by a single zero-day but by systemic weak credential hygiene compounded by a legacy password-storage weakness in FortiOS.
Fortinet introduced PBKDF2-based password hashing for administrator credentials in FortiOS 7.2.11, 7.4.8, and 7.6.1, replacing a legacy SHA-256-based storage mechanism. Critically, when a device is upgraded from an earlier version, existing administrator passwords remain stored as SHA-256 hashes until the corresponding administrator successfully logs in following the upgrade — leaving a large population of upgraded-but-not-re-authenticated devices with crackable legacy hashes. Threat actors have been systematically extracting configuration files from internet-facing FortiGate devices (via exposed management interfaces, prior breach access, or leaked backups) and cracking the stored SHA-256 hashes offline, then combining the results with credentials harvested from earlier Fortinet-related breach dumps and infostealer logs.
The resulting credential database is continuously revalidated against internet-facing FortiGate devices via automated authentication attempts. Once a device is compromised, it is frequently repurposed as a listening post to passively monitor SSL VPN traffic, harvesting additional live credentials that feed back into the scanner — creating a self-sustaining feedback loop that has driven the campaign's scale. Investigators identified a large fraction of compromised accounts as generic administrative or Fortinet built-in system accounts (e.g., 'admin' variants ~21.4%, 'fgts*' system accounts ~6.95%, 'fort*' system accounts ~5.4-6%, 'telm*' ISP-provisioned accounts ~2.36%), and Fortinet's own PSIRT analysis separately flagged suspicious admin account names to monitor for: forticloud, fortiuser, fortinet-support, fortinet-tech-support.
The campaign closely tracks — and in reporting is frequently conflated/overlapped with — active in-the-wild exploitation of a cluster of Fortinet FortiCloud SSO authentication-bypass vulnerabilities: CVE-2025-59718 and CVE-2025-59719 (improper verification of cryptographic signature in FortiCloud SSO SAML handling, CVSS 9.8/9.1 depending on source, disclosed December 2025, added to CISA KEV December 16 2025) and CVE-2026-24858 (authentication bypass allowing a FortiCloud account holder to authenticate to devices registered under other FortiCloud accounts when SSO is enabled, CVSS 9.8, CWE-288, disclosed January 27 2026, added to CISA KEV the same day). Fortinet observed two malicious FortiCloud accounts actively exploiting CVE-2026-24858 in the wild before locking them out on 2026-01-22, and disabled FortiCloud SSO server-side on 2026-01-26. Both advisory families (FG-IR-25-647 and FG-IR-26-060) are explicitly referenced in Fortinet's own PSIRT analysis of the FortiBleed credential compromise as related, actively-exploited authentication weaknesses in the same feature surface (FortiCloud SSO / admin authentication).
Attribution work by SOCRadar (published June 29, 2026) tentatively links the campaign's infrastructure, tooling choices, and victim-selection patterns to the Lynx/INC Ransom group (also tracked as INC Ransomware), a Russian-speaking ransomware-as-a-service operation active since 2023 with a documented focus on NATO member states and adjacent countries. Analysts noted that defense-industry VPN endpoint credentials were recovered from an exposed operator server, and that the operation's server infrastructure (260+ operational servers, 80,000+ unique IPs, 22,405+ unique domains observed) is organized by country, sector, and victim organization revenue — consistent with pre-ransomware initial-access broker tradecraft rather than opportunistic credential stuffing alone.
Confirmed and probable victims span government (591 entries across 111 domains, ~60% India), telecommunications (5,616 entries, the most-targeted vertical), healthcare, education, energy, banking, manufacturing, universities, and large commercial enterprises (>20% of entries from organizations with >$1B revenue), with primary geographic concentration in North America and Europe alongside global (194-country) reach. CISA issued a public alert (2026-06-18) urging organizations to harden internet-facing Fortinet devices in direct response to the campaign, and multiple national CERTs (including cyber.gc.ca) have separately issued guidance on the related FortiCloud SSO CVEs.
MITRE ATT&CK techniques used in TL-2026-1232
Credential Access
T1003 OS Credential Dumping; T1040 Network Sniffing; T1110 Brute Force; T1110.003 Brute Force: Password Spraying; T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1087.002 Account Discovery: Domain Account
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares; T1210 Exploitation of Remote Services; T1550 Use Alternate Authentication Material
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1070.003 Indicator Removal: Clear Command History
Collection
T1039 Data from Network Shared Drive; T1119 Automated Collection; T1602.002 Data from Configuration Repository: Network Device Configuration Dump
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Command and Control
T1090 Proxy; T1090.002 Proxy: External Proxy; T1095 Non-Application Layer Protocol; T1102.002 Web Service: Bidirectional Communication; T1572 Protocol Tunneling; T1573.002 Encrypted Channel: Asymmetric Cryptography
Persistence
T1098 Account Manipulation; T1136 Create Account; T1505 Server Software Component; T1542 Pre-OS Boot
Impact
T1486 Data Encrypted for Impact; T1495 Firmware Corruption; T1498 Network Denial of Service; T1531 Account Access Removal
defense-impairment
T1556 Modify Authentication Process; T1685.001 Disable or Modify Windows Event Log; T1685.002 Disable or Modify Cloud Log; T1685.006 Clear Linux or Mac System Logs; T1686 Disable or Modify System Firewall
Resource Development
T1583 Acquire Infrastructure; T1583.003 Acquire Infrastructure: Virtual Private Server; T1583.004 Acquire Infrastructure: Server; T1583.008 Acquire Infrastructure: Malvertising; T1584.005 Compromise Infrastructure: Botnet; T1585 Establish Accounts; T1586 Compromise Accounts; T1588 Obtain Capabilities; T1588.002 Obtain Capabilities: Tool
Reconnaissance
T1589 Gather Victim Identity Information; T1592 Gather Victim Host Information; T1595 Active Scanning; T1595.001 Active Scanning: Scanning IP Blocks
Affected products and versions in FortiBleed: Mass Credential Compromise Campaign Against
- Fortinet — FortiOS
Vulnerable versions: 7.0.0-7.0.18; 7.2.0-7.2.12; 7.4.0-7.4.10; 7.6.0-7.6.5
Fixed in: 7.4.11; 7.6.6; 8.0.x (with PBKDF2 password hashing) - Fortinet — FortiManager
Vulnerable versions: 7.0.0-7.0.15; 7.2.0-7.2.11; 7.4.0-7.4.9; 7.6.0-7.6.5
Fixed in: 7.4.10 or later; 7.6.6 or later - Fortinet — FortiAnalyzer
Vulnerable versions: 7.0.0-7.0.15; 7.2.0-7.2.11; 7.4.0-7.4.9; 7.6.0-7.6.5
Fixed in: 7.4.10 or later; 7.6.6 or later - Fortinet — FortiProxy
Vulnerable versions: 7.0.0-7.0.22; 7.2.0-7.2.15; 7.4.0-7.4.12; 7.6.0-7.6.4
Fixed in: 7.6.5 or later - Fortinet — FortiWeb
Vulnerable versions: 7.4.0-7.4.11; 7.6.0-7.6.6; 8.0.0-8.0.3
Fixed in: 8.0.4 or later - Fortinet — FortiNAC-F
Vulnerable versions: 7.6.3-7.6.5
Fixed in: 7.6.6 or later - Fortinet — FortiSwitchManager
Vulnerable versions: affected by CVE-2025-59718/59719 SAML SSO bypass
Fixed in: latest per FG-IR-25-647 advisory
Remediation for FortiBleed: Mass Credential Compromise Campaign Against
Patches
- Upgrade FortiOS to 7.4.11 or 7.6.6 (or later) to remediate CVE-2026-24858
- Upgrade to FortiOS 7.2.11, 7.4.8, 7.6.1 or later to obtain PBKDF2-based administrator password hashing (replaces legacy SHA-256 storage)
- Upgrade affected FortiAnalyzer, FortiManager, FortiNAC-F, FortiProxy, and FortiWeb builds per FG-IR-26-060 and FG-IR-25-647 fixed-version tables
- After any FortiOS upgrade, require every administrator to log in at least once post-upgrade to force migration off legacy SHA-256 password hashes to PBKDF2
Immediate actions
- Terminate all active administrator and SSL VPN sessions on internet-exposed FortiGate devices
- Force a full password reset for every local administrator and VPN account, including built-in/default accounts (admin, forticloud, fortiuser, fortinet-support, fortinet-tech-support)
- Disable FortiCloud SSO login on all devices until confirmed patched and re-authenticated
- Audit local administrator account lists for unrecognized or renamed accounts created post-compromise
- Review SSL VPN and admin login logs for authentications from unexpected source IPs/ASNs or impossible-travel patterns
Workarounds
- If unable to patch immediately, fully disable the 'Allow administrative login using FortiCloud SSO' toggle on every registered device
- Apply local-in policies / trusted-host restrictions to lock admin GUI and SSH access to specific known-good source IPs
- Geo-fence or ACL VPN and management ports (443, 4443, 8443, 10443) at the perimeter where business need does not require global reachability
Longer-term hardening
- Enforce mandatory multi-factor authentication on all administrative and SSL VPN accounts
- Restrict management interface (HTTPS admin GUI, SSH) access to trusted internal networks / VPN-only, never expose to the public internet
- Implement enterprise password policy prohibiting reuse of previously breached credentials; integrate breach-credential monitoring
- Rotate credentials on a recurring schedule and after any suspected exposure event
- Deploy centralized logging/SIEM correlation for FortiGate admin and VPN authentication events with alerting on brute-force/credential-stuffing patterns
CVEs associated with FortiBleed: Mass Credential Compromise Campaign Against
Weaknesses (CWE) in FortiBleed: Mass Credential Compromise Campaign Against
CWE-288, CWE-347, CWE-521, CWE-798, CWE-916, CWE-287, CWE-289, CWE-22, CWE-306, CWE-787
Timeline of FortiBleed: Mass Credential Compromise Campaign Against
Showing the 20 most recent tracked events.
- Wiz Threat Center publishes initial incident report identifying the FortiBleed credential compromise campaign against internet-exposed Fortinet devices.
- Arctic Wolf Labs publishes analysis confirming FortiBleed campaign activity impacting Fortinet devices across 194 countries, ~30,791+ confirmed compromised devices.
- PwnDefend corroborates attribution of the threat-actor infrastructure IP 85.11.187.8.
- UK NCSC publishes a coordinated advisory alongside CISA urging organizations to harden internet-facing Fortinet devices and investigate for compromise.
- Eclypsium publishes 'FortiBleed: You Can't Patch Your Way Out of This', detailing symlink persistence in /data/etc/ and /data/lib/ and the hidden old-password design flaw.
- Bitdefender publishes technical advisory on the FortiBleed credential exposure campaign; CISA issues a public alert urging hardening of internet-facing Fortinet devices.
- Fortinet PSIRT publishes 'Analysis of reported credential compromise of FortiGate devices,' attributing root cause to credential reuse/brute-force against weak/legacy password hygiene and referencing FG-IR-26-060 and FG-IR-25-647; recommends upgrade to FortiOS 7.4, 7.6, or 8.0 for PBKDF2 hashing.
- Sophos publishes an advisory correlating the FortiBleed credential exposure with a related, distinct VPN-bruteforcing campaign against Sophos Firewall appliances lacking MFA.
- Dark_Alpha posts a Darkforums listing offering FortiGate/Fortinet access spanning 35,000 IPs across 194 countries for $25,000, in the data format url:user:pass:domain:revenue.
- Cloud Security Alliance and Huntress publish independent research notes on FortiBleed default-credential exploitation and mass compromise scope.
- A secondary, lower-credibility actor branding itself 'shinymontanna'/ShinyHunters attempts to re-extort victims and resell the harvested dataset.
- Dark_Alpha posts a second, U.S.-focused Darkforums listing offering 6,355 verified FortiGate accesses for $7,000 in bulk, accepting forum escrow payments.
- NCSC advisory last modified/updated.
- Fortinet publishes a formal response to the FortiBleed campaign findings.
- Sophos publishes an update confirming that successful compromises among its customers were limited strictly to devices that lacked MFA protection.
- Palo Alto Networks Unit 42 publishes a threat brief on the large-scale credential attack campaign, corroborating scope and methodology.
- SOCRadar publishes research tentatively attributing FortiBleed campaign infrastructure and victim-selection patterns to the Lynx/INC Ransom group, reporting 86,644 compromised FortiGate devices across 194 countries, 260+ operational servers, 80,000+ unique IPs, and 22,405+ unique domains.
- Wiz publishes 'Agentless Threat Hunting: FortiGate' detailing CVE-2026-24858 exploitation TTPs and framing virtual appliances as an EDR-incompatible cloud blind spot.
- Qualys publishes follow-up research on FortiBleed credential reuse and internet-exposed FortiGate risk.
- CISA adds the related FortiOS vulnerability CVE-2025-68686 (symbolic-link persistence patch bypass, CWE-200) to the Known Exploited Vulnerabilities catalog.
Update history for TL-2026-1232
- 2026-08-31 — FortiBleed: Global Credential-Compromise Campaign Exposes 86,644+ Fortinet FortiGate Firewalls via SHA-256 Hash Harvesting and FortiCloud SSO Bypass (CVE-2026-24858, CVE-2025-68686): What changed No change to severity/exploitability/status/CVSS (all remain CRITICAL/ACTIVE/9.8). The newer report adds a related CVE (CVE-2025-68686, symlink-persistence patch bypass, CVSS 5.9, added to CISA KEV 2026-07-27) and confirms two
- 2026-07-22 — FortiGate Zero-Day (CVE-2026-24858) and FortiBleed Credential-Stuffing Campaign Expose Virtual Appliance Blind Spot: What changed No field escalations — severity, exploitability, and status remain CRITICAL/ACTIVE/ACTIVE as already recorded. This update is additive intelligence, not an escalation. New indicators (15) 14 new indicators: specific rogue admin
- 2026-07-18 — FortiBleed: Mass Credential Compromise Across 73,932 FortiGate Firewalls via Chained Fortinet CVEs and Symlink Persistence: What changed No field escalation — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and CVSS (9.8) all already at maximum in the existing record. The update is additive: it extends the vulnerability chain and adds a persistenc
- 2026-07-18 — FortiBleed: Russian IAB SantaAd's Living-off-the-Land Credential-Harvesting Campaign Compromises 430,000+ Fortinet, Sophos, Synology, and MSSQL Systems, Exposing 110M+ Credentials: What changed No field escalations applied. Severity/exploitability/status unchanged (new report's severity_level HIGH is lower than the existing CRITICAL — a downgrade, so not applied per escalation-only rule). New indicators (18) 18 new IO
- 2026-07-18 — FortiBleed Credential Exposure Exploited: Initial Access Broker Dark_Alpha Selling FortiGate Access on Darkforums: What changed Severity HIGH → CRITICAL: the FortiBleed credential exposure is now confirmed to be actively monetized on the Darkforums cybercrime marketplace by initial access broker Dark_Alpha (two bulk listings, 35,000 and 6,355 verified a
Sources cited for FortiBleed: Mass Credential Compromise Campaign Against
- FortiBleed: Credential Compromise Campaign Targeting Fortinet Devices
- Analysis of reported credential compromise of FortiGate devices
- Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries
- FortiBleed: 86,644 Fortinet Firewalls Compromised — SOCRadar Research
- FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
- Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices
- Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls, VPN gateways
- FortiBleed: Default Credential Exploitation and Mass Fortinet Compromise
- FortiBleed Security Alert: Fortinet VPN Credentials Exposed
- 2026-June Fortibleed Credential Exposure – Huntress Support
- CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
- Fortinet Releases Guidance to Address Ongoing Exploitation of Authentication Bypass Vulnerability CVE-2026-24858
- Administrative FortiCloud SSO authentication bypass (FG-IR-26-060)
- Multiple Fortinet Products' FortiCloud SSO Login Authentication Bypass (FG-IR-25-647)
- CVE-2026-24858 Detail - NVD
Threats related to FortiBleed: Mass Credential Compromise Campaign Against
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware
- FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations
- FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN Gateways
- FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 Protocols
- FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations
Detection coverage for TL-2026-1232
As of 2026-08-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1232 across Splunk SPL, Microsoft KQL and Sigma, covering 89 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1232
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.