logo

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

ID: aa606406-78bb-5510-a025-96e2a403670a

STIX ID: report--aa606406-78bb-5510-a025-96e2a403670a

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

Author: [email protected] (The Hacker News)

...
...

The FortiBleed campaign is a financially motivated, Russian-speaking initial-access operation active since Feb 2026 that used mass scanning and brute-force to compromise FortiGate firewalls and other appliances; operators deployed a Golang tool (FortigateSniffer) leveraging FortiOS diagnostic packet sniffing to capture cleartext credentials and hashes across 24 protocols. The campaign reportedly impacted ~430,000 FortiGate devices, ran at least 659 credential-harvesting pipelines, and led to the collection of over 110 million credentials and authentication tokens; stolen data was cracked, validated, reused for Active Directory access and lateral movement, and exfiltrated, with pipelines organized by region, time-of-day geofencing, and automated orchestration (hash cracking via Hashmat/Hashtopolis and HASHBOT).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.