Infostealers FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally
Article Content
- •Over 75,000 Fortinet devices compromised, affecting 194 countries.
- •Attackers used previously leaked credentials and conducted over 1.16 billion credential attempts.
- •Major corporations and government agencies are among the victims, highlighting the campaign's extensive reach.
A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously leaked credentials and conducted over 1.16 billion credential attempts against FortiGate devices. The exposed dataset includes verified usernames and passwords for major corporations and government agencies, allowing potential unauthorized access to sensitive networks. Researchers identified the campaign's extensive reach, with significant impacts on sectors such as telecommunications, healthcare, and government. The operation is ongoing, with automated tools continuously testing the compromised credentials. Security experts emphasize the need for immediate password changes and enhanced security measures. Fortinet acknowledged the situation but stated it was not linked to any recent vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (105)
Following this threat?
Track Accenture in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomhouse Targets Pertamina in Latest Ransomware Attack Ransomhouse has claimed a new victim, Pertamina, following the exposure of FortiOS SSL-VPN credentials due to the 'FortiBleed' vulnerability (CVE-2022-40684). This vulnerability was publicly disclosed on October 18, 2022, and has been actively exploited since October 11, 2022. The attack has led to the publication of…
Multiple Ransomware Attacks Target Various Organizations In September 2026, multiple organizations, including watchops.com and geekybunch.com, were reported as victims of ransomware attacks by the group known as 'unsafe'. The incidents were listed on dark web leak sites, but details regarding the nature of the attacks, such as data encryption or theft, remain vague. The…