FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices
A newly discovered data leak dubbed FortiBleed has exposed Fortinet VPN credentials for 73,932 firewall URLs at organizations worldwide. Consequently, security researchers warn that the leaked data could enable direct access to enterprise networks.
What Happened: FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices
Security researcher Bob Diachenko discovered an exposed server containing what appears to be valid Fortinet and FortiGate VPN credentials. Also, the database included usernames, email addresses, and plaintext passwords for major global organizations.
According to Diachenko’s investigation, a Russian-speaking threat group allegedly conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets. Furthermore, the attackers used a 45-GPU cluster managed through Hashtopolis to crack intercepted SSL VPN authentication hashes.
Hudson Rock later analyzed the dataset and confirmed it contains 73,932 unique firewall URLs across 194 countries. Moreover, the leak impacts 21,632 unique domains spanning nearly every major industry sector.
Technical Details of the FortiBleed Incident
The leaked data includes comments listing each organization’s industry, revenue, and number of employees. Therefore, the information was likely collected for planning targeted attacks.
Kevin Beaumont independently reviewed the data and confirmed the credentials are authentic. He also found that roughly 75,000 Fortinet devices remain online and exposed. Moreover, Beaumont determined the data originated from exported Fortinet configurations rather than brute-forced credentials alone.
The affected IP addresses differ from the 2025 Belsen Group Fortinet leak. Thus, FortiBleed represents a separate and more recent collection of compromised devices.
- 73,932 unique firewall URLs leaked
- 21,632 unique domains impacted
- Data spans 194 countries
- Many devices run relatively recent FortiOS versions
- Approximately half of all internet-accessible Fortinet firewalls affected
Business and Operational Impact
The FortiBleed leak poses severe risks to enterprise security. For example, organizations listed in the dataset include Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Siemens, Lenovo, PwC, Accenture, and Oracle.
Moreover, multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were fully compromised. A Turkish NATO defense contractor was also allegedly breached, with classified documents stolen.
- Direct network access: Valid VPN credentials allow attackers to bypass perimeter defenses
- Lateral movement: Compromised credentials enable pivoting into Active Directory environments
- Critical infrastructure risk: Government agencies and infrastructure operators appear in the dataset
- Supply chain exposure: Major manufacturers and IT service providers are affected
- Compliance implications: Breach notification and regulatory scrutiny likely for impacted organizations
Mitigation and Recommendations
Organizations must act immediately to reduce exposure from the FortiBleed leak. Therefore, the following steps should be taken without delay.
Immediate Actions for Defenders
- Rotate all Fortinet VPN and administrative passwords immediately
- Enforce multi-factor authentication on all FortiGate interfaces
- Examine gateway logs for suspicious authentication activity
- Audit FortiOS configurations for unauthorized changes or exported files
- Scan for exposed employee credentials using Hudson Rock’s FortiBleed lookup tool
Long-Term Hardening Steps
Organizations should also restrict FortiGate management interfaces from direct internet exposure. Furthermore, network segmentation should limit VPN access to essential systems only. Regular credential rotation and monitoring for leaked credentials should become standard practice.
Bottom line: FortiBleed exposes credentials for roughly half of all internet-accessible Fortinet firewalls. Rotate passwords, enforce MFA, and audit logs immediately.
Incident Summary
| Incident Name: | FortiBleed |
| Affected Systems: | Fortinet FortiGate SSL VPN firewalls (~73,000 devices) |
| Disclosure Date: | June 17, 2026 |
| Patch Status: | N/A — credential leak, not a software vulnerability |
| Attribution: | Russian-speaking multi-operator threat group |
| Countries Affected: | 194 countries; highest impact in India, United States, Taiwan, Mexico, Turkey |
| Key Discovery: | Bob Diachenko (security researcher) |
References
- Lawrence Abrams, “FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices,” BleepingComputer, June 17, 2026, https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/
- Bob Diachenko, LinkedIn post on FortiBleed discovery, June 2026, https://www.linkedin.com/feed/update/urn:li:activity:7471222472193830913/
- Hudson Rock, “FortiBleed: 75,000 Fortinet Firewalls Compromised — Global Enterprises Exposed,” Infostealers.com, June 2026, http://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/
- Kevin Beaumont, “FortiBleed: 75k Fortinet firewalls have admin passwords cracked,” DoublePulsar, June 2026, https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8
- CISA, Known Exploited Vulnerabilities Catalog, https://www.cisa.gov/known-exploited-vulnerabilities-catalog