FortiBleed is a massive credential theft campaign targeting over 70,000 Fortinet FortiGate firewalls and SSL VPN devices globally. Attackers, linked
The threat intelligence platform InfoStealers revealed a massive credential leakage incident named "FortiBleed" on June 17, 2026[1]. Login credentials for over 70,000 FortiGate firewalls and SSL VPN devices produced by US company Fortinet globally were stolen and leaked by hackers, and the dataset is currently circulating in underground criminal communities[2]. Upon learning of this, the Cybersecurity Agency immediately issued a cybersecurity alert and notified government agencies and Critical Infrastructure (CI) authorities to take protective measures; no related hacker intrusion reports have been received domestically so far[1]. Researchers estimate that affected devices account for approximately half of all internet-exposed Fortinet devices globally, involving organizations such as multinational corporations, government agencies, and critical infrastructure[1].
Attackers are suspected to be linked to Russian-speaking cybercrime groups and possess capabilities for large-scale scanning, credential validation, and automated attacks[1]. Researchers analyzed that attackers launched approximately 1.16 billion login credential attempts against over 320,000 FortiGate devices and conducted about 2.1 billion brute-force attacks against over 160,000 Microsoft SQL Server (MSSQL) servers[1]. The attack strategy includes intercepting SSL VPN authentication hash values and performing offline cracking via a large cluster composed of 45 GPUs managed by Hashtopolis[1].
The core technical vulnerability in this attack lies in the gap between the legacy credential hash mechanism (SHA-256) and the upgraded PBKDF2 algorithm, which requires re-login to become effective[1]. Fortinet upgraded the algorithm from SHA-256 to PBKDF2 in early 2025, but the update requires re-login to activate, causing many devices to still store credentials in the legacy format[1]. Once configuration files are leaked, attackers can systematically brute-force these hash values using the 45-GPU offline cracking architecture, significantly increasing the risk of credential compromise[1]. No new FortiOS vulnerabilities have been found in this incident; the data may originate from historical leakage incidents or accounts/passwords obtained via brute-force attacks[1].
Affected devices are distributed globally, with approximately 50% of internet-exposed Fortinet devices potentially impacted[1]. After successfully obtaining valid credentials, attackers may further pivot horizontally into internal Active Directory environments to establish and maintain long-term access[1]. Besides attempting to use previously leaked or infrequently changed account passwords, the group also actively intercepts SSL VPN authentication hash values, demonstrating highly automated attack capabilities[1]. Current public information does not fully explain the initial acquisition method of relevant device configuration files and authentication hash values; actual causes of impact may include reuse of data leaked from historical incidents, brute-forced weak passwords, exposed management interfaces on the internet, and unauthorized acquisition of device configuration files[1].
To reduce the risk of credential misuse and unauthorized device access, enterprise management teams should take the following response measures: First, terminate connections and reset passwords, interrupt all ongoing administrator sessions, and comprehensively reset passwords for Fortinet VPN and administrator accounts[1]. Second, fully enable Multi-Factor Authentication (MFA), ensuring MFA is enabled for all administrator accounts and VPN user accounts to effectively prevent credential leakage risks[1]. Third, upgrade FortiOS and verify password hash formats, upgrading devices to the latest version supporting the PBKDF2 algorithm and removing older legacy encryption settings per official guidance[1]. Fourth, review device accounts and configuration content, checking whether firewall, VPN user lists, and other settings have been unauthorizedly tampered with, and watch for hidden unknown accounts such as "forticloud," "fortiuser," etc.[1]. Finally, restrict public access to management interfaces, promptly verify whether device management interfaces are exposed to the internet, recommend removing them from the public internet, and allow access only via trusted IPs or through jump servers/VPNs[1].