logo

74,000 Fortinet firewall credentials exposed in FortiBleed data leak

ID: 0f8b195f-fb62-5516-a32e-b00de287a88f

STIX ID: report--0f8b195f-fb62-5516-a32e-b00de287a88f

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Zeljka Zorz

...
...

A Russian-speaking cybercriminal group harvested and exposed credentials from configuration files for about 73,932 Fortinet firewalls and VPN gateways worldwide (dubbed “FortiBleed”), using intercepted SSL VPN authentication hashes cracked on a 45-GPU cluster and leveraging exposed FortiGate management interfaces; many high-profile organizations and government entities are affected, with confirmed compromises and exfiltration in some cases. The report urges immediate remediation (rotate credentials, enforce MFA, upgrade FortiOS, remove management interfaces from the internet) and provides a lookup tool for affected organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.