FortiBleed: 73,932 Fortinet Firewalls Compromised — Credential Extraction Campaign Analysis

Global telemetry analysis of FortiBleed: mass unauthenticated credential extraction targeting 73,932 Fortinet appliances.

FortiBleed: 73,932 Fortinet Firewalls Compromised — Credential Extraction Campaign Analysis
📌
Security Roundup Series: Week of June 18, 2026 • 4 min read deep dive
🏛️
Incident Overview: Victim / Target: 73,932 Fortinet FortiGate Firewalls Exposed Records: Global SSL-VPN credential sets & session tokens

This post is part of the Week of June 19, 2026 Security Roundup.

Overview

The FortiBleed campaign is a large-scale, systematic operation that has extracted and cracked administrator credentials from 73,932 Fortinet FortiGate firewall instances across 194 countries. Unlike a single zero-day exploit, FortiBleed is better understood as a convergence of known, unpatched Fortinet CVEs, weak password hashing, and infostealer credential recycling — resulting in verified working admin credentials for an estimated 30,000–75,000 devices globally.

Technical Root Causes

Hudson Rock and Arctic Wolf's analysis identifies three contributing factors:

1. Known CVEs on Unpatched Devices

The primary exploitation vector is a chain of previously disclosed Fortinet vulnerabilities — most notably CVE-2026-24858 and related path traversal / authentication bypass flaws — that enable unauthenticated access to configuration data including hashed credentials on unpatched FortiOS versions. Many organizations have not applied Fortinet patches from 2025–2026, leaving these known attack surfaces open.

2. Crackable SHA-256 Password Hashing

Older FortiOS versions stored administrator passwords as unsalted or weakly salted SHA-256 hashes. Modern GPU-based hashcat campaigns can crack common and dictionary-based passwords in minutes to hours. Attackers extracted configuration backups or credential hashes via the known CVEs, then cracked them offline.

3. Credential Reuse from Infostealer Campaigns

A portion of the credentials in the FortiBleed dataset appear to have originated from infostealer malware (RedLine, Vidar, etc.) on administrator workstations, subsequently validated against FortiGate management interfaces. This "combo list" approach accelerates credential validation at scale.

Scale and Impact

  • 73,932 unique FortiGate firewall URLs identified with extracted credentials
  • 21,632 affected domains
  • 194 countries — globally distributed
  • Verified working admin credentials for an estimated 30,000–75,000 devices
  • Affected organizations span critical infrastructure, healthcare, financial services, and government

CVE Chain

  • CVE-2026-24858 — FortiOS path traversal enabling config file access (primary vector)
  • CVE-2026-25089 — FortiSandbox unauthenticated RCE (separate but exploited in parallel by the same threat actor cluster)
  • Additional older Fortinet auth bypass CVEs enabling credential hash extraction on FortiOS 7.x and earlier

Detection

Signs your FortiGate may be in the FortiBleed dataset:

  • Check Hudson Rock's public indicator list (link in references) for your firewall's public IP
  • Audit administrator account last-login timestamps for unexpected access
  • Review FortiGate logs for config export operations you did not initiate
  • Monitor for admin logins from unexpected geographic locations or IP ranges

Remediation

# 1. Immediately rotate ALL FortiGate administrator passwords
#    Use strong, unique passwords (20+ chars, random)

# 2. Apply all pending Fortinet patches — prioritize:
#    FortiOS 7.4.x -> 7.4.5+
#    FortiOS 7.2.x -> 7.2.10+
#    FortiOS 7.0.x -> 7.0.17+

# 3. Restrict management interface access
config system interface
  edit 
    set allowaccess https ssh
    set trusted-hosts 
  next
end

# 4. Enable multi-factor authentication for all admin accounts
# FortiGate Admin -> System -> Administrators -> Edit -> Two-factor Authentication

# 5. Verify password hashing strength (FortiOS 7.2+ uses bcrypt by default)
get system status | grep "FortiOS"

# 6. If your IP is in the FortiBleed dataset, treat management credentials as fully compromised:
#    - Rotate VPN pre-shared keys
#    - Rotate SSL-VPN user credentials
#    - Audit firewall policy changes for unauthorized rules
#    - Check for backdoor admin accounts

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther