THE Security Affairs piece reports that FortiBleed, a credential-h harvesting operation targeting Fortinet FortiGate firewalls, compromised 86,644 devices across 194 countries. The attackers used credentials that were already exposed or weakly protected, rather than exploiting a newly patched software flaw. Investigators verified the operation's scale via an open backend directory exposing its inner workings, including target selection, credential validation workflows, and how access was prepared for sale.
The campaign relies on credential stuffing and password spraying, with harvested hashes fed into GPU-accelerated cracking tools to produce plaintext passwords at scale.
According to the advisory cited by the article, the attackers move beyond simple access by enriching and sorting compromised accounts, removing honeypots, and prioritising targets for revenue and network structure. They establish new admin accounts on affected firewalls, map Active Directory, and then continue lateral movement.
A worrying feature for defenders is post-compromise activity: threat actors have deleted or altered passwords on existing accounts to lock organisations out, while sometimes creating new accounts to maintain persistence. The article notes that stolen access has been bought and sold to initial access brokers supplying ransomware groups, with INC/Lynx and Payload named as current buyers, meaning a credential-stuffing event today could lead to encryption of networks tomorrow.
Mitigation echoed in the advisory includes restricting external management access to trusted systems, ideally removing internet-facing admin entirely; ending active admin and VPN sessions; resetting passwords on exposed systems; and implementing phishing-resistant MFA for remote access and admin accounts. Fortinet also highlights that legacy SHA-256 password storage significantly aided cracking, recommending PBKDF2 for administrator passwords on FortiOS 7.2.11 and later.