Skip to content
Security Alert - FortiBleed Credential Leak Incident: Over 70,000 Fortinet Devices Suspected ...

Security Alert - FortiBleed Credential Leak Incident: Over 70,000 Fortinet Devices Suspected ...

Hkcert • June 18, 2026

HKCERT alerts organisations to a recent credential leakage incident known as FortiBleed. The incident involves the exposure of data and credentials related to Fortinet firewalls and VPN devices.

According to recent threat intelligence and media reports, attackers are suspected to have obtained a large number of valid login credentials for Fortinet devices. These credentials may be used to gain unauthorised access to affected organisations’ devices and internal networks. Research also suggests that attackers may be conducting automated testing using previously leaked usernames and passwords to identify Fortinet credentials that remain valid. In some cases, the management interfaces of affected devices are directly exposed to the Internet, further increasing the risk of compromise.

If attackers successfully gain access to such devices, they may use them to further access the organisation’s internal network, conduct lateral movement, steal additional account information, modify system settings, or deploy malware, ransomware, or other backdoors on internal systems. This may pose further risks to business operations and information security.

The incident is reported to affect devices in more than 194 countries, and the leaked data may involve approximately 74,000 Fortinet devices. Based on publicly available information, some organisations in Hong Kong may also be affected.

HKCERT urges all organisations using Fortinet firewalls and VPN-related devices to review their risk exposure immediately. Organisations may also check whether their domain appears in the relevant dataset through the following website to assess whether they may be affected by the data leakage incident:

HKCERT recommends that organisations take the following actions:

If an organisation suspects that data relating to its Fortinet devices has been exposed, it should immediately:

Businesses or members of the public who wish to report to HKCERT on information security related incidents such as malware, phishing, denial of service attacks, etc. can do so by completing the online form at: , or calling the 24-hour hotline at +852 8105 6060. For further enquiries, please HKCERT at [email protected] .

Extracted Entities

Campaigns (1)

Companies (1)

MITRE ATT&CK (1)