FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls
ID: 447485e8-69e2-539d-920c-d5113bdf1f17
STIX ID: report--447485e8-69e2-539d-920c-d5113bdf1f17
Feed Name: CosmicBytez Labs
FortiBleed is a large-scale credential-harvesting campaign active since February 2026 that targets internet-facing FortiGate firewalls using known FortiOS vulnerabilities and credential-stuffing/password-spraying against default or weak accounts; the harvested VPN/admin credentials (reported >110M) are validated, packaged, and sold by a Russian-speaking initial access broker on criminal markets, enabling ransomware and other intrusions. The report provides attack phases, actor profile, impact assessment, detection indicators, and prioritized mitigation steps (patch FortiOS, enable MFA, rotate credentials, review logs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
