Cyber & Technology — 2026-06-17
FortiBleed Leak Exposes Fortinet VPN Credentials for 73000 Firewall Devices Worldwide
BLUFPublicly confirmed intrusions attributed to the FortiBleed credential trove are unlikely before mid-September, as most affected organizations have not yet recognized their perimeters as breached.
Security researcher Bob Diachenko discovered an exposed server containing Fortinet VPN credentials; Hudson Rock's analysis identified 73,932 firewall URLs across 194 countries, with entries for Foxconn, Samsung, Comcast, Oracle, and government agencies 123. SOCRadar, which independently detected the same threat actor infrastructure, reported a lower count of 30,791 compromised devices and attributed the campaign to a Russian-speaking multi-operator group 4. Diachenko's investigation of the exposed server found the group had executed an estimated 1.16 billion credential attempts against 320,000 FortiGate targets, cracking intercepted SSL VPN hashes with a 45-GPU cluster 13. Researcher Kevin Beaumont independently confirmed multiple credentials as authentic; Diachenko separately reported alleged classified document theft from a Turkish NATO defense contractor, a claim Fortinet had not publicly confirmed 12.
AnalysisPublicly confirmed attribution of FortiBleed-derived intrusions at named organizations is
unlikely by September 15, 2026. High analytic confidence rests on consistent precedent: breach attribution rarely surfaces within months of credential exposure. The attackers' self-reinforcing compromise cycle, harvesting new credentials from already-breached VPN traffic, extends dwell time and complicates forensic traceability. Nearly all compromised devices remain online, indicating affected organizations have not treated this as a perimeter breach. The exposed dataset may instead be an aggregated compilation from prior breach events rather than novel active collection, which would substantially narrow real-time exploitation risk. If attribution does surface before the September deadline, enterprise security executives face pressure toward mandatory perimeter-breach posture and regulatory bodies may issue emergency directives.
4 sources
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices - BleepingComputer
- FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries - HackRead
- FortiBleed - 70,000+ Fortinet Firewalls Compromised in Massive Exploitation Attack - Cyber Security News
- FortiBleed: The Compromise of 30,000 Fortinet Firewalls - SOCRadar
View in full brief →