The "FortiBleed" campaign targets internet-facing Fortinet FortiGate firewalls through the systematic exploitation of vulnerabilities to extract sensitive configuration files. These files contain administrative credential hashes, which threat actors subject to offline cracking attacks to obtain plaintext credentials. The campaign has impacted 86,644 devices across 194 countries, resulting in the compromise of an estimated 30,000 to 75,000 verified administrator accounts. This widespread access enables threat actors to achieve full administrative control over network infrastructure, facilitating lateral movement, data exfiltration, and persistent network compromise within highly sensitive enterprise environments.
-
Incident Overview: Global Campaign Scale
- Coordinated campaign identified in mid-June 2026 targeting Fortinet's edge security infrastructure.
- Massive geographic footprint spanning 194 countries, affecting nearly every global region.
- Total identified targets reach 86,644 FortiGate devices.
-
Attack Vector: Configuration Extraction & Cracking
- Exploitation of vulnerabilities to facilitate the unauthorized download of device configuration files.
- Extraction of files containing administrative credential hashes (e.g., SHA-256, bcrypt, or proprietary formats).
- Transition from active exploitation to offline brute-force/cracking of hashes to bypass network-based detection.
-
Threat Impact: Administrative Takeover
- Estimated 30,000 to 75,000 verified administrative credentials successfully compromised.
- Risk level classified as Critical due to the potential for full administrative control over network gateways.
- Potential for attackers to leverage compromised firewalls for lateral movement and deep network infiltration.
-
Defensive Actions: Detection & Mitigation
- Immediate application of Fortinet PSIRT-recommended firmware updates to close configuration extraction vectors.
- Mandatory rotation of all administrative credentials following a confirmed or suspected breach.
- Enforcement of multi-factor authentication (MFA) for all administrative access to mitigate the impact of cracked hashes.
- Implementation of logging and monitoring for anomalous configuration download requests and unauthorized access patterns.
Related posts
- techjacksolutions.com — FortiBleed: Mass Credential Compromise Campaign Targeting 86,644 FortiGate Devices Across 194 Countries
- arcticwolf.com — Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries
- Recordedfuture
- Fortinet
- Dataprise
- Labs
- Beazley