FortiBleed: Over 86,000 Fortinet Firewalls Compromised Worldwide

cyber-news 2026-06-19 3 min read

Key Takeaways:

  • A database of over 86,644 working credentials for Fortinet FortiGate firewalls from 194 countries has been discovered.
  • The attack, dubbed FortiBleed, relies on automated scanning, past password leaks, and VPN traffic sniffing rather than a zero-day vulnerability.
  • Victims include governments (over 111 domains), telecoms, and major corporations (over 20% are enterprises with >$1B in revenue).

The cybersecurity world has been shaken by a new, active campaign named FortiBleed. SOCRadar researchers have uncovered a server belonging to a hacking group that contained a massive database of over 86,000 verified, working usernames and passwords for Fortinet FortiGate network security devices. If your organization relies on these solutions, your network might already be compromised.

"What we found was not just a list of stolen passwords. We found the entire operation: the tools, the automation, the victim list, and enough identifying information to build a detailed picture of who is behind it."
- SOCRadar Researchers

How Were the Firewalls Compromised?

Interestingly, unlike many high-profile attacks from the past, FortiBleed does not exploit a 0-day vulnerability. The attack is largely based on poor security hygiene and full automation:

  1. Hackers scan the internet for FortiGate devices.
  2. They test a database of known, previously leaked passwords, hoping that administrators haven’t changed them (which proves to be a highly effective strategy).
  3. After a successful login, they use the compromised device as a listening post to passively monitor SSL VPN traffic, intercepting more passwords transmitted over the network and fueling the attack cycle.

The vast majority of compromised accounts are default administrator and system accounts whose names and passwords were never changed since installation.

The Massive Scale and Geopolitical Backdrop

The list of victims spans organizations from almost every industry across 194 countries. It is particularly alarming that the telecommunications sector (over 5,600 devices) and government institutions (591 entries across 111 domains) have been heavily targeted. The countries with the highest number of compromised devices are India and the United States, but the attack has reached virtually every corner of the globe.

Clues such as target selection, the tools used, and the infrastructure strongly suggest that Russian-speaking cybercriminals are behind the attack. Targeting NATO member states and government facilities implies that the operation has geopolitical motives alongside financial ones.

How to Protect Your Network?

If your organization uses Fortinet devices, you must act immediately:

  • Change all passwords: Refresh credentials for all administrative and VPN accounts, especially those that haven’t been changed in a long time.
  • Enable 2FA: Two-factor authentication should be an absolute requirement for any account with remote access.
  • Restrict panel access: The firewall’s administrative panel should never be directly accessible from the public internet.
  • Update software: Ensure that the firmware on your device has the latest security patches.

FAQ

Is FortiBleed a new zero-day vulnerability in Fortinet systems?
No. Current analyses do not point to the exploitation of an unknown vulnerability. The attack relies on past password leaks, brute-force attacks, and capturing more data by sniffing VPN traffic inside already compromised networks.
Has the FortiBleed database been leaked on the dark web?
At the time of the SOCRadar report publication, the database was not yet offered on criminal forums. The campaign is still ongoing, making immediate response and device securing critical before access is sold to other threat groups.
GADNET Team
We build Zero Trust solutions to protect your home network and privacy in a smart way.