Infostealers
FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously leaked credentials and conducted over 1.16 billion credential attempts against FortiGate devices. The exposed dataset includes verified usernames and passwords for major corporations and government agencies, allowing potential unauthorized access to sensitive networks. Researchers identified the campaign's extensive reach, with significant impacts on sectors such as telecommunications, healthcare, and government. The operation is ongoing, with automated tools continuously testing the compromised credentials. Security experts emphasize the need for immediate password changes and enhanced security measures. Fortinet acknowledged the situation but stated it was not linked to any recent vulnerabilities.
Key Points: • Over 75,000 Fortinet devices compromised, affecting 194 countries. • Attackers used previously leaked credentials and conducted over 1.16 billion credential attempts. • Major corporations and government agencies are among the victims, highlighting the campaign's extensive reach.