"FortiBleed" Massive Credential Theft Campaign:...

FortiBleed is a massive credential theft campaign targeting over 70,000 Fortinet FortiGate firewalls and SSL VPN devices globally. Attackers, linked

Event Description

The threat intelligence platform InfoStealers revealed a massive credential leakage incident named "FortiBleed" on June 17, 2026[1]. Login credentials for over 70,000 FortiGate firewalls and SSL VPN devices produced by US company Fortinet globally were stolen and leaked by hackers, and the dataset is currently circulating in underground criminal communities[2]. Upon learning of this, the Cybersecurity Agency immediately issued a cybersecurity alert and notified government agencies and Critical Infrastructure (CI) authorities to take protective measures; no related hacker intrusion reports have been received domestically so far[1]. Researchers estimate that affected devices account for approximately half of all internet-exposed Fortinet devices globally, involving organizations such as multinational corporations, government agencies, and critical infrastructure[1].

Technical Analysis

Attackers are suspected to be linked to Russian-speaking cybercrime groups and possess capabilities for large-scale scanning, credential validation, and automated attacks[1]. Researchers analyzed that attackers launched approximately 1.16 billion login credential attempts against over 320,000 FortiGate devices and conducted about 2.1 billion brute-force attacks against over 160,000 Microsoft SQL Server (MSSQL) servers[1]. The attack strategy includes intercepting SSL VPN authentication hash values and performing offline cracking via a large cluster composed of 45 GPUs managed by Hashtopolis[1].

The core technical vulnerability in this attack lies in the gap between the legacy credential hash mechanism (SHA-256) and the upgraded PBKDF2 algorithm, which requires re-login to become effective[1]. Fortinet upgraded the algorithm from SHA-256 to PBKDF2 in early 2025, but the update requires re-login to activate, causing many devices to still store credentials in the legacy format[1]. Once configuration files are leaked, attackers can systematically brute-force these hash values using the 45-GPU offline cracking architecture, significantly increasing the risk of credential compromise[1]. No new FortiOS vulnerabilities have been found in this incident; the data may originate from historical leakage incidents or accounts/passwords obtained via brute-force attacks[1].

Scope of Impact

Affected devices are distributed globally, with approximately 50% of internet-exposed Fortinet devices potentially impacted[1]. After successfully obtaining valid credentials, attackers may further pivot horizontally into internal Active Directory environments to establish and maintain long-term access[1]. Besides attempting to use previously leaked or infrequently changed account passwords, the group also actively intercepts SSL VPN authentication hash values, demonstrating highly automated attack capabilities[1]. Current public information does not fully explain the initial acquisition method of relevant device configuration files and authentication hash values; actual causes of impact may include reuse of data leaked from historical incidents, brute-forced weak passwords, exposed management interfaces on the internet, and unauthorized acquisition of device configuration files[1].

Protection Recommendations

To reduce the risk of credential misuse and unauthorized device access, enterprise management teams should take the following response measures: First, terminate connections and reset passwords, interrupt all ongoing administrator sessions, and comprehensively reset passwords for Fortinet VPN and administrator accounts[1]. Second, fully enable Multi-Factor Authentication (MFA), ensuring MFA is enabled for all administrator accounts and VPN user accounts to effectively prevent credential leakage risks[1]. Third, upgrade FortiOS and verify password hash formats, upgrading devices to the latest version supporting the PBKDF2 algorithm and removing older legacy encryption settings per official guidance[1]. Fourth, review device accounts and configuration content, checking whether firewall, VPN user lists, and other settings have been unauthorizedly tampered with, and watch for hidden unknown accounts such as "forticloud," "fortiuser," etc.[1]. Finally, restrict public access to management interfaces, promptly verify whether device management interfaces are exposed to the internet, recommend removing them from the public internet, and allow access only via trusted IPs or through jump servers/VPNs[1].

5-Step Remediation Checklist

  • Step 1: Immediately terminate all administrator sessions and comprehensively reset Fortinet VPN and administrator account passwords.
  • Step 2: Mandatorily enable Multi-Factor Authentication (MFA) for all administrator accounts and VPN user accounts.
  • Step 3: Upgrade devices to the latest FortiOS version supporting the PBKDF2 algorithm and remove older legacy encryption settings.
  • Step 4: Review firewall and VPN configuration content, confirm no unauthorized tampering, and investigate unknown accounts such as "forticloud".
  • Step 5: Remove management interfaces from the public internet, allowing access only via trusted IPs or through jump servers/VPNs.

References

  • TWCERT News: "FortiBleed" Massive Credential Theft Campaign: Enterprise Firewalls and VPN Devices Face Risks
  • Liberty Financial: Over 70,000 Global Device Credentials Hacked and Leaked! Cybersecurity Agency Issues Urgent Alert
  • Central News: US Company Fortinet Login Credentials Suspected Leaked, Cybersecurity Agency Issues Alert
  • Bitsight: FortiBleed Security Alert: Fortinet VPN Credentials Exposed

More cybersecurity news