Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
Incident

FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

By ogwatermelon
June 18, 2026 3 Min Read
0
June 17, 2026

A newly discovered data leak dubbed FortiBleed has exposed Fortinet VPN credentials for 73,932 firewall URLs at organizations worldwide. Consequently, security researchers warn that the leaked data could enable direct access to enterprise networks.

What Happened: FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

Security researcher Bob Diachenko discovered an exposed server containing what appears to be valid Fortinet and FortiGate VPN credentials. Also, the database included usernames, email addresses, and plaintext passwords for major global organizations.

According to Diachenko’s investigation, a Russian-speaking threat group allegedly conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets. Furthermore, the attackers used a 45-GPU cluster managed through Hashtopolis to crack intercepted SSL VPN authentication hashes.

Hudson Rock later analyzed the dataset and confirmed it contains 73,932 unique firewall URLs across 194 countries. Moreover, the leak impacts 21,632 unique domains spanning nearly every major industry sector.

Technical Details of the FortiBleed Incident

The leaked data includes comments listing each organization’s industry, revenue, and number of employees. Therefore, the information was likely collected for planning targeted attacks.

Kevin Beaumont independently reviewed the data and confirmed the credentials are authentic. He also found that roughly 75,000 Fortinet devices remain online and exposed. Moreover, Beaumont determined the data originated from exported Fortinet configurations rather than brute-forced credentials alone.

The affected IP addresses differ from the 2025 Belsen Group Fortinet leak. Thus, FortiBleed represents a separate and more recent collection of compromised devices.

  • 73,932 unique firewall URLs leaked
  • 21,632 unique domains impacted
  • Data spans 194 countries
  • Many devices run relatively recent FortiOS versions
  • Approximately half of all internet-accessible Fortinet firewalls affected

Business and Operational Impact

The FortiBleed leak poses severe risks to enterprise security. For example, organizations listed in the dataset include Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Siemens, Lenovo, PwC, Accenture, and Oracle.

Moreover, multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were fully compromised. A Turkish NATO defense contractor was also allegedly breached, with classified documents stolen.

  • Direct network access: Valid VPN credentials allow attackers to bypass perimeter defenses
  • Lateral movement: Compromised credentials enable pivoting into Active Directory environments
  • Critical infrastructure risk: Government agencies and infrastructure operators appear in the dataset
  • Supply chain exposure: Major manufacturers and IT service providers are affected
  • Compliance implications: Breach notification and regulatory scrutiny likely for impacted organizations

Mitigation and Recommendations

Organizations must act immediately to reduce exposure from the FortiBleed leak. Therefore, the following steps should be taken without delay.

Immediate Actions for Defenders

  1. Rotate all Fortinet VPN and administrative passwords immediately
  2. Enforce multi-factor authentication on all FortiGate interfaces
  3. Examine gateway logs for suspicious authentication activity
  4. Audit FortiOS configurations for unauthorized changes or exported files
  5. Scan for exposed employee credentials using Hudson Rock’s FortiBleed lookup tool

Long-Term Hardening Steps

Organizations should also restrict FortiGate management interfaces from direct internet exposure. Furthermore, network segmentation should limit VPN access to essential systems only. Regular credential rotation and monitoring for leaked credentials should become standard practice.

Bottom line: FortiBleed exposes credentials for roughly half of all internet-accessible Fortinet firewalls. Rotate passwords, enforce MFA, and audit logs immediately.

Incident Summary

Incident Name: FortiBleed
Affected Systems: Fortinet FortiGate SSL VPN firewalls (~73,000 devices)
Disclosure Date: June 17, 2026
Patch Status: N/A — credential leak, not a software vulnerability
Attribution: Russian-speaking multi-operator threat group
Countries Affected: 194 countries; highest impact in India, United States, Taiwan, Mexico, Turkey
Key Discovery: Bob Diachenko (security researcher)

References

  1. Lawrence Abrams, “FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices,” BleepingComputer, June 17, 2026, https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/
  2. Bob Diachenko, LinkedIn post on FortiBleed discovery, June 2026, https://www.linkedin.com/feed/update/urn:li:activity:7471222472193830913/
  3. Hudson Rock, “FortiBleed: 75,000 Fortinet Firewalls Compromised — Global Enterprises Exposed,” Infostealers.com, June 2026, http://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/
  4. Kevin Beaumont, “FortiBleed: 75k Fortinet firewalls have admin passwords cracked,” DoublePulsar, June 2026, https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8
  5. CISA, Known Exploited Vulnerabilities Catalog, https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Tags:

Incident
Author

ogwatermelon

Follow Me
Other Articles
Previous

Mastra npm Supply Chain Attack: 144 Packages Compromised

Next

CISA Orders Federal Patch for Joomla JCE CVE-2026-48907 by Friday

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.