Tuesday , September 8 2026
FortiBleed

FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

A vast cyber spying operation called “FortiBleed” has quietly compromised more than 73,932 different Fortinet firewall URLs in 194 countries.

Figure 1: A snippet from the leaked database showing successfully compromised Fortinet credentials, revealing the sheer scale of the automated collection.

Originally discovered by security researcher Volodymyr “Bob” Diachenko, with more study from Hudson Rock and cyber expert Kevin Beaumont, this dataset shows a huge, automated scheme. Bad actors managed to hit 73,932 different firewall URLs in 194 countries, leading to 21,632 unique affected domains. Shockingly, as Beaumont pointed out, this makes up about 50% of all Fortinet firewall devices online.

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
India: C-DOT Launches 14 Local Quantum-Safe Technologies

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Microsoft has launched Project Zenith, a new Windows 11 experience for developers. It is made for powerful PCs that can...
Read More
Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Google issues warning of new Chrome zero-day flaw exploited

Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws....
Read More
Google issues warning of new Chrome zero-day flaw exploited

Methodology & Unprecedented Scale

According to Diachenko’s investigative report, This campaign is run by a group of Russian-speaking cybercriminals from different companies. The scale of the operation is huge: the attackers made about 1.16 billion attempts to steal credentials from more than 320,000 FortiGate targets, plus an extra 2.1 billion brute-force attempts aimed at over 160,000 MSSQL servers.

The group’s methodology goes beyond simple credential reuse. They actively intercept SSL VPN authentication hashes and crack them using a massive, dedicated 45-GPU cluster managed via Hashtopolis. Once the perimeter is breached, the operators move quickly into the internal Active Directory to stay connected to the network.

Diachenko found that many organizations in Japan, Taiwan, Vietnam, Iraq, and Turkey were fully hacked. Most importantly, a Turkish NATO defense contractor was affected, and the group stole important defense papers from them.

Beaumont notes a sharp contrast between this incident and the prior “Belsen Group” leak of 15,000 devices from a 2022 zero-day. This dataset represents active, recent compromises—with many of the affected devices running recent patches.

Fortinet credentials Exposed (Source: Diachenko)

Beaumont noticed that the way the leaked data is organized, which sorts victims by company type, income, and country, is typical of eCrime groups selling initial access on the dark web.

As Beaumont explains in his blog, the attackers likely exploited older credential hashing mechanisms to pull this off. While Fortinet hardened admin credential storage in early 2025 by moving to PBKDF2, this protection only applied if administrators actively logged in after applying the firmware updates. Consequently, many devices continued storing credentials using the older, more vulnerable SHA-256 with Salt format, making them highly susceptible to offline brute-forcing once the configuration files were extracted.

High-Profile Victims Identified

The impact of this breach affects almost all parts of the global economy and hits every industry. The attackers have created a real database with working login details for some of the biggest companies in the world.

Among the victims discovered in this dataset are massive multinational corporations, including:

Technology & Manufacturing: Foxconn, Samsung, Siemens, Lenovo, Oracle
Professional Services: PwC, Accenture
Telecommunications: Comcast
and thousands of government entities and critical infrastructure providers

“Lenovo said it was looking into it”, the register reported.

Mitigation Steps

Organizations using Fortinet devices must see this as a serious and active threat and take action right away:

Force Credential Rotation: Reset all Fortinet VPN and admin interface passwords without delay; complexity is irrelevant if credentials have already leaked.
Enforce Universal MFA: Apply Multi-Factor Authentication across all external gateways to neutralize stolen plaintext credentials.
Audit Gateway Logs: Review Fortinet access logs for anomalous login locations, unexpected admin sessions, or unusual traffic volumes.
Restrict Management Interface Exposure: Apply local-in policies to restrict admin panel access to trusted internal IPs only, and disable FortiCloud SSO if not essential.

“Fortinet is aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways. We are committed to safeguarding our customers, and we diligently and continuously monitor threat actor darknet activity,” Fortinet told in a statement .

“Based on our analysis, the data involved is a resharing of data from previous incidents, as well as bruteforcing of credentials, and is not related to any recent incident or advisory. Organizations that follow routine best practices, including regularly refreshing security credentials, as per guidance in this March blog, face minimal risk from credential compromise detail referenced in the reporting.”

“Fortinet continues to investigate these reports with the security of our customers as our top priority.”

Check Also

FalconFlank

CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

An unnamed security expert known as “Nightmare Eclipse” shared a CrowdStrike Falcon zero-day exploit called …