FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally

FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally

First seen 17 Jun 2026, 15:25 UTC InfostealersDarkreadingCybersecuritynewsBleepingcomputerTheregister+63 87% similarity 75.0

Article Content

Browse articles
ThreatCluster

A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously leaked credentials and conducted over 1.16 billion credential attempts against FortiGate devices. The exposed dataset includes verified usernames and passwords for major corporations and government agencies, allowing potential unauthorized access to sensitive networks. Researchers identified the campaign's extensive reach, with significant impacts on sectors such as telecommunications, healthcare, and government. The operation is ongoing, with automated tools continuously testing the compromised credentials. Security experts emphasize the need for immediate password changes and enhanced security measures. Fortinet acknowledged the situation but stated it was not linked to any recent vulnerabilities.

Key Points: • Over 75,000 Fortinet devices compromised, affecting 194 countries. • Attackers used previously leaked credentials and conducted over 1.16 billion credential attempts. • Major corporations and government agencies are among the victims, highlighting the campaign's extensive reach.

ThreatCluster AI How this analysis works

Timeline

2026-06-16
FortiBleed campaign discovered
Security researcher Volodymyr Diachenko identified an exposed server containing Fortinet credentials, leading to the investigation of the campaign.
Darkreading
2026-06-17
Credential leak details published
Reports revealed that the FortiBleed campaign exposed over 73,932 Fortinet VPN credentials, affecting major organizations worldwide.
Bleepingcomputer
2026-06-18
Fortinet acknowledges ongoing threat
Fortinet confirmed the credential theft campaign but stated it was not linked to any recent vulnerabilities, urging users to change passwords.
Cybernews

Community

Browse all →