FortiBleed: The 2026 Fortinet Credential-Harvesting Campaign That Exposed 430,000 Firewalls
What Is FortiBleed?
FortiBleed is the name given to a massive credential-harvesting campaign targeting Fortinet FortiGate devices, first publicly disclosed on June 17, 2026. Security researcher Bob Diachenko discovered a misconfigured attacker-controlled server containing valid administrative and SSL VPN credentials for over 73,000 FortiGate firewalls across 194 countries and 21,632 unique organizational domains.
The dataset — independently verified by threat intelligence firm Hudson Rock and researcher Kevin Beaumont — was described as one of the largest known troves of compromised Fortinet-related credentials ever discovered. Within 24 hours, CISA, the UK NCSC, and Canada's Centre for Cyber Security all issued emergency alerts. By the end of June, the campaign's true scale had expanded to an estimated 430,000 compromised firewalls and 110 million harvested credentials.
How FortiBleed Actually Worked
FortiBleed was not a single zero-day vulnerability. It was an industrialized, multi-stage credential-harvesting operation that combined several attack techniques into a devastating pipeline:
- Credential reuse from prior breaches: The attackers leveraged credentials stolen through earlier Fortinet vulnerabilities — including CVE-2026-24858 (FortiCloud SSO authentication bypass, CVSS 9.8) and CVE-2025-59718 (FortiCloud SSO SAML bypass, CVSS 10) — both of which had been actively exploited in the wild.
- Brute-force at AI speed: Using automated tools, the threat actors conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets, plus an additional 2.1 billion attempts against Microsoft SQL Server systems.
- SSL VPN hash interception: A custom Golang tool called
FortigateSnifferabused FortiOS's nativediagnose sniffer packetdiagnostic command to passively intercept SSL VPN authentication traffic across two dozen protocols — turning each compromised firewall into a wiretap at the network boundary. - GPU-accelerated cracking: Intercepted authentication hashes were fed into a 45-GPU cracking cluster managed through Hashtopolis, cracking passwords offline at industrial scale.
- Configuration file extraction: Stolen FortiGate configuration backups — many containing administrator passwords stored as legacy SHA-256 hashes rather than PBKDF2 — were systematically collected and cracked.
The Scale of the Breach
The numbers paint a sobering picture of the largest credential exposure in Fortinet's history:
| Metric | Figure |
|---|---|
| Affected FortiGate devices | 73,932 initially confirmed; 430,000+ by end of June |
| Countries affected | 194 |
| Unique organizational domains | 21,632 |
| Total credentials harvested | 110 million+ |
| Credential attempts against FortiGate | 1.16 billion |
| Devices with sniffer installed | ~12,000 |
| Confirmed ransomware deployments | 12+ (with hundreds of endpoints encrypted) |
The affected organizations span nearly every major industry: Chevron and Sinopec in energy; Samsung, Foxconn, Lenovo, and Toyota in manufacturing; Comcast and AT&T in telecommunications; Oracle and Accenture in technology; Siemens and PwC in professional services. A Turkish NATO-affiliated defense contractor was also identified in the dataset.
Kevin Beaumont estimated the dataset covers approximately 50% of all internet-reachable FortiGate devices worldwide.
The Ransomware Connection
On July 2, 2026, SOCRadar researchers made a critical breakthrough: an operational security failure on the attackers' own infrastructure directly linked the FortiBleed credential-harvesting campaign to INC Ransom and Lynx — two of the most active ransomware-as-a-service operations in 2026.
The evidence was direct. A member of the initial access broker crew behind FortiBleed was found logged into the affiliate negotiation panels of both ransomware operations simultaneously, from infrastructure tied to the campaign. At least 12 ransomware deployments have been confirmed, with hundreds of endpoints encrypted across affected organizations.
This is how the ransomware economy functions in 2026: the people who break in are not the people who encrypt. A single upstream compromise — one campaign against one vendor's firewalls — fans out into dozens of downstream extortion events, spread across multiple ransomware brands, months after the original credential theft.
Why Patching Wasn't Enough
One of the most unsettling findings from FortiBleed: many of the devices from which configuration files were stolen had already been patched. The organizations applied the vendor fix. They followed the advisory guidance. What they did not do was change their administrative passwords after patching.
The configuration backup files, stolen before the patch was applied, contained hashed admin credentials. Those hashes — many still stored using the older SHA-256 algorithm rather than PBKDF2 — were cracked offline at scale using GPU clusters. Fortinet introduced PBKDF2-based password hashing in FortiOS 7.2.11, 7.4.8, and 7.6.1, but existing administrator passwords remain stored as SHA-256 hashes until the administrator manually logs in following the upgrade. Many organizations never completed that step.
This is the fourth distinct Fortinet security event in 2026 alone — following AI-assisted exploitation of FortiGate in February, FortiClient EMS takeover in early June, and FortiSandbox exploitation in mid-June. The pattern is unmistakable: patching appliances without rotating credentials is an incomplete response.
Why the Appliance Model Is the Root Cause
FortiBleed is not a Fortinet problem — it's an architecture problem. Every physical or virtual firewall appliance that exposes a management interface or SSL VPN portal to the internet is a potential entry point. When credentials leak from one device, attackers don't just access that device — they pivot into the internal network, establish Active Directory persistence, and operate undetected for months.
Consider what organizations affected by FortiBleed now face:
- Rotating every administrative and VPN password across their entire Fortinet fleet
- Auditing configuration files for unauthorized changes
- Hunting for Active Directory persistence mechanisms planted months ago
- Monitoring for ransomware deployment from credentials that were sold to multiple affiliates
- Repeating this process every time a new Fortinet vulnerability is disclosed
The underlying issue is that managing network security through individual appliances creates an ever-expanding operational burden. Every device is a separate attack surface. Every credential is a separate risk. Every patch is a separate maintenance window. For mid-market IT teams with limited staff, this model is unsustainable.
How a SASE Platform Eliminates This Attack Surface
A Secure Access Service Edge (SASE) platform fundamentally changes the architecture in ways that make campaigns like FortiBleed irrelevant to your organization:
No Exposed Management Interfaces
With a cloud-native SASE platform like Jimber, there are no physical or virtual firewall appliances with management interfaces exposed to the internet. Security policies are configured through a cloud management console protected by multi-factor authentication, role-based access control, and continuous monitoring — not through a device sitting in your server room that attackers can scan, brute-force, and exploit.
No Credentials to Steal from Configuration Files
Because there are no appliance configuration files to exfiltrate, there are no hashed administrator passwords for attackers to crack with GPU clusters. Authentication is handled through the cloud platform's identity provider, with modern hashing, MFA enforcement, and continuous session validation — not through locally stored credential hashes that persist long after a patch is applied.
Zero Trust by Default
SASE platforms enforce Zero Trust Network Access at every layer. No device, user, or workload is trusted by default. Even if credentials were compromised, lateral movement within the network is blocked because there is no implicit trust between network segments. The blast radius of a credential leak is contained to the specific resource the credential was issued for — not the entire network.
Continuous Updates Without Intervention
Because SASE is delivered as a cloud service, security updates, hashing algorithm upgrades, vulnerability patches, and new threat intelligence are deployed automatically. There is no "did we remember to have every administrator log in after the upgrade so PBKDF2 activates" — the platform handles it. Your IT team focuses on your business, not on appliance maintenance schedules.
What Should You Do If You Run Fortinet Appliances?
If your organization operates FortiGate devices — especially those with internet-facing management interfaces or SSL VPN portals — take these steps immediately:
- Check if you're in the dataset: Multiple security vendors have published lookup services following the FortiBleed disclosure. Verify whether your devices appear in the exposed credential set.
- Terminate all sessions and rotate credentials: Terminate every active SSL VPN and administrative session. Reset all Fortinet VPN and administrator passwords, prioritizing internet-facing systems. Do this even if you believe your devices were patched — the stolen configuration files predate the patches.
- Complete PBKDF2 migration: Upgrade to FortiOS 7.2.11, 7.4.8, or 7.6.1+. After upgrading, ensure every administrator logs in at least once to trigger the migration from SHA-256 to PBKDF2 hashing. Manually remove legacy hash settings.
- Enforce MFA everywhere: Multi-factor authentication on all administrator and VPN user accounts is no longer optional. FortiBleed succeeded primarily against devices without MFA and with weak password hygiene.
- Hunt for Active Directory persistence: The FortiBleed crew's pattern is admin-level access followed by durable AD footholds. Credential rotation alone does not evict an attacker who has planted persistence mechanisms. Review domain controller logs for lateral movement, unusual access patterns, and suspicious account creation.
- Plan your migration off appliances: FortiBleed is the fourth distinct Fortinet security event in 2026. The pattern will repeat. Use this as the catalyst to evaluate a cloud-native SASE architecture that eliminates appliance management entirely.
Conclusion: The Appliance Model Is the Vulnerability
FortiBleed is not an isolated incident — it is the logical outcome of an architecture where every organization independently manages, patches, and secures hundreds or thousands of internet-facing appliances. When 50% of all internet-reachable FortiGates can be compromised in a single campaign, the problem is not the vendor. The problem is the model.
Jimber's SASE platform eliminates the need for VPN concentrators, secure web gateways, and firewall appliances by delivering network security as a cloud service. There are no configuration files to exfiltrate, no SHA-256 hashes to crack, no SSL VPN portals to brute-force, and no management interfaces exposed to the internet. Security happens in the cloud, continuously updated, so your IT team can focus on what actually matters — protecting your business, not patching appliances.
Want to see how Jimber SASE eliminates your appliance attack surface? Request a demo today.