FortiBleed Campaign: AI-Driven Exploitation of Fortinet Firewalls

FortiBleed Campaign: AI-Driven Exploitation of Fortinet Firewalls

First seen 21 Jun 2026, 15:36 UTC Infostealerswww.hudsonrock.com 93% similarity 66.8

Article Content

Browse articles
ThreatCluster

The FortiBleed campaign exposed valid credentials for nearly 75,000 Fortinet FortiGate firewalls across 21,632 domains. Threat actors leveraged commoditized supercomputing resources to execute massive cryptographic attacks, previously the domain of state intelligence agencies. By renting a 36-GPU cluster from Vast.ai, they efficiently cracked passwords from harvested encrypted configuration files. The attackers utilized AI-assisted tools for managing their operations, including code editors and penetration testing frameworks. This incident highlights a significant shift in cybercrime, where financial motivation and advanced technology allow attackers to bypass traditional security measures. The impact is extensive, affecting numerous enterprises relying on Fortinet devices. The campaign underscores the need for enhanced security protocols to defend against such sophisticated threats.

Key Points: • FortiBleed compromised 75,000 Fortinet firewalls, affecting 21,632 domains. • Attackers utilized a 36-GPU cluster rented from Vast.ai for password cracking. • AI tools were employed for managing operations and automating penetration testing.

ThreatCluster AI How this analysis works

Timeline

2026-06-21
FortiBleed campaign disclosed
Hudson Rock researchers revealed the exposure of credentials for 75,000 Fortinet firewalls, marking a significant breach.
Infostealers

Community

Browse all →