securityaffairs.com 6/22/2026, 11:30:51 AM · external

Russian hackers steal 110M credentials from 430k FortiGate devices

Russian hackers steal 110M credentials from 430k FortiGate devices
CyberSIXT Evidence Panel
Primary Source socradar.io

THE article details the FortiBleed operation, a significant Russian credential-harvesting campaign affecting over 430,000 FortiGate firewalls and capturing around 110 million credentials. Conducted by SOCRadar's Threat Research Unit (STRU), the report outlines the campaign's sophisticated five-phase attack chain, using custom tools and exploiting common vulnerabilities.

The infrastructure, believed to be operated by Russian actors, targets mostly small and medium-sized businesses globally, with a notable impact on sectors like IT services. Recommendations for organizations include rotating credentials, implementing MFA, and reviewing logs for unusual activity.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline