logo

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems

ID: 86b8a26f-3d75-52ac-8f1f-0a55400d8d96

STIX ID: report--86b8a26f-3d75-52ac-8f1f-0a55400d8d96

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

...
...

## Executive Summary A dataset called "FortiBleed" allegedly exposes valid administrative and SSL VPN credentials for ~73,932 FortiGate firewall URLs across 194 countries; researchers validated sampled credentials and linked the campaign to a Russian-speaking threat group that targeted government, critical infrastructure, and multinational organizations. Attackers reportedly harvested exported FortiGate configs, intercepted SSL VPN hashes, used a 45-GPU cracking cluster (Hashcat/Hashtopolis) to recover plaintext credentials, and used those credentials for Active Directory access and follow-on intrusions; Recorded Future identified infrastructure artifacts and an associated IP (85.11.187.8). The report urges immediate credential rotation, MFA enforcement, log review, interface exposure reduction, patching, and internal hunt for compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.