IC Technology & Surveillance — 2026-06-21
CISA Issues Emergency Advisory After FortiBleed Campaign Compromises 86644 Fortinet Credentials Across 194 Countries Including Government Networks
BLUFFull device-configuration extraction across roughly half of all internet-facing Fortinet firewalls demands remediation well beyond credential rotation, yet public confirmation by affected government networks remains unlikely within 90 days of the June 18 advisory.
On June 18, CISA confirmed that threat actors were actively using FortiBleed credentials against Fortinet firewalls and VPN gateways across government and private-sector organizations in 194 countries 12. Hudson Rock's analysis of data first discovered by researcher Bob Diachenko on an exposed server counted 73,932 unique firewall URLs across 21,632 domains, with named entries including Foxconn, Samsung, Siemens, PwC, and multiple government agencies 23. Diachenko's review of tooling the attackers inadvertently left accessible attributed the campaign to a Russian-speaking multi-operator group that ran approximately 1.16 billion credential attempts against FortiGate targets, with a Turkish NATO defense contractor named among alleged victims from which classified documents were reportedly stolen 23. Researcher Kevin Beaumont independently verified credentials at multiple listed organizations and concluded the data originated from exported device configurations rather than credential interception, covering roughly half of all internet-facing Fortinet firewalls 23.
AnalysisThe configuration-export origin, confirmed by Beaumont's independent verification at named organizations, extends remediation beyond credential rotation to backdoor accounts and configuration tampering, since full device-level access was required to produce the dataset. A US or Five Eyes government agency publicly confirming unauthorized access within 90 days of the June 18 CISA advisory is
unlikely, since disclosure culture and classification constraints consistently suppress public acknowledgment well past remediation milestones. Moderate confidence reflects the CISA primary advisory and Beaumont's verification, constrained by the unresolved initial access vector and no confirmed government victim statements. The dataset may originate from a previously patched Fortinet vulnerability rather than a new undisclosed flaw, in which case patched organizations face only historical credential exposure. Absent public government confirmation, credential rotation stands as the remediation ceiling; confirmed access would trigger mandatory reporting, backdoor hunts, and hardware replacement.
4 sources
- CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
- CISA Warns of Active Exploitation Following FortiBleed Leak - Security Affairs
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices - BleepingComputer
- FortiBleed: 86000 Fortinet Device Credentials Compromised - SecurityWeek
View in full brief →