All incidents

FortiBleed credential leak exposes tens of thousands of Fortinet devices

campaignclosedJun 19, 2026 — Jun 21, 2026
FortiBleed credential leak exposes tens of thousands of Fortinet devices

A credential‑spraying campaign dubbed FortiBleed has exposed the login details of tens of thousands of Fortinet firewalls and VPN gateways, prompting an urgent warning from the Cybersecurity and Infrastructure Security Agency the agency warned. The leak, first spotted in mid-June 2026, affects organisations across government and industry and is already being used in active attacks worldwide.

The exposure stems from FortiGate devices whose administrative interfaces were left reachable from the public internet without proper authentication controls, allowing attackers to scrape valid usernames and passwords, as detailed in a recent industry roundup noted by Security Affairs. Because no software vulnerability is being exploited, the attack relies solely on credential reuse; there is no associated CVE identifier or CVSS score for the flaw itself.

Researchers linked the harvested credentials to a database that now contains over 86 000 unique device logins, with attempts originating from more than 190 countries, a figure echoed in separate reporting that cited roughly 74 000 compromised units according to Security Affairs. Attackers have already made roughly 1.16 billion authentication attempts against FortiGate systems, succeeding in compromising a number of critical-infrastructure providers and corporate networks.

CISA noted that a Russian-speaking threat actor is behind the campaign, using the credential set to gain persistent access to firewalls and VPN concentrators. While no specific advanced persistent threat group has been named, the activity shows a clear pattern of credential spraying followed by lateral movement inside victim networks, a campaign highlighted in a SecurityWeek analysis detailing the scale of the operation.

The incident highlights how a simple configuration mistake can lead to a massive credential leak, reinforcing the need for systematic device hardening, a point reiterated in the CISA advisory restating the urgency of mitigation. It mirrors previous leaks where exposed management consoles became a foothold for ransomware and espionage operations, showing that device-level hygiene remains a core defence.

Organisations should immediately rotate all passwords for FortiGate management accounts, enforce multi-factor authentication where supported, and restrict administrative access to trusted IP ranges or jump hosts, steps that align with the hardening checklist published by Security Affairs in its latest roundup. Reviewing authentication logs for abnormal spikes, disabling unused services, and applying the latest firmware patches are also recommended to prevent reuse of the leaked credentials.

Intelligence briefing updated Jun 21, 2026

Root sourcewww.cisa.gov
Timeline Coverage

Swipe to explore timeline