logo

FortiBleed Exploit Campaign Hits 70,000+ Fortinet Firewalls Worldwide

ID: cf0d3321-f67d-5a84-8b06-e3259bc2b495

STIX ID: report--cf0d3321-f67d-5a84-8b06-e3259bc2b495

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Divya

...
...

FortiBleed is a widespread exploitation campaign that exposed 73,932 Fortinet devices across 194 countries by extracting configuration files and offline credential hashes, enabling ~1.16 billion credential attempts and subsequent administrative logins, lateral movement, and data exfiltration; victims include major corporations and government entities. The operation is linked to a Russian‑speaking criminal group using automated scanning and a 45‑GPU cracking cluster (Hashtopolis) to rapidly recover passwords, and investigators recommend removing public management access, full credential rotation and rehashing under PBKDF2, MFA enforcement, and forensic response to assume persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.