Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries
ID: af5b74cc-cd80-5e6d-af41-c24d9bd2042c
STIX ID: report--af5b74cc-cd80-5e6d-af41-c24d9bd2042c
Feed Name: DataBreaches.Net
A large-scale campaign named FortiBleed has been observed actively extracting FortiGate configuration files and cracking stored administrator credential hashes, yielding verified working admin credentials for an estimated 30,000–75,000 devices across 194 countries. The success is linked to legacy SHA-256 password storage persisting after upgrades and datasets of confirmed credentials have been found organized by country and sector, indicating broad operational infrastructure and active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
