Critical Fortinet FortiGate SSL VPN RCE Vulnerability Exploited in Attacks
Key Takeaways A vast cyber espionage operation, dubbed “FortiBleed,” has compromised over 73,932 Fortinet firewall URLs globally. The campaign, attributed to a Russian-speaking group,...
Key Takeaways
- A vast cyber espionage operation, dubbed “FortiBleed,” has compromised over 73,932 Fortinet firewall URLs globally.
- The campaign, attributed to a Russian-speaking group, leverages stolen credentials from infostealer malware and targets FortiGate devices and SSL VPN gateways.
- Attackers have gained deep, persistent access to internal Active Directory environments and exfiltrated sensitive data, including classified defense documents.
- Password complexity offered no protection against compromise, as credentials were often stolen in plaintext before encryption.
- Organizations are urged to implement immediate mitigation steps, including forced credential rotation and universal MFA.
“FortiBleed” Campaign Compromises Tens of Thousands of Fortinet Firewalls
A sophisticated cyber espionage campaign, now identified as “FortiBleed,” has stealthily infiltrated more than 73,932 unique Fortinet firewall URLs spanning 194 countries. This industrial-scale operation has targeted FortiGate devices and their associated SSL VPN gateways on an unprecedented global scale.
Table Of Content
The extent of this widespread compromise was initially brought to light by security researcher Volodymyr “Bob” Diachenko, with subsequent in-depth analysis provided by Hudson Rock. Their findings reveal a highly automated attack infrastructure.
Attack Modus Operandi and Scale
Threat actors engaged in an estimated 1.16 billion credential-based login attempts against over 320,000 FortiGate targets. Concurrently, they executed an additional 2.1 billion brute-force attempts against more than 160,000 MSSQL servers, ultimately leading to the compromise of 21,632 distinct domains.
This extensive campaign is attributed to a multi-operator, Russian-speaking cybercriminal collective. Their methodology extends far beyond simple credential stuffing, indicating a highly organized and technically proficient group.
The attackers systematically scanned the internet for exposed Fortinet instances. These identified targets were then subjected to credential validation against vast databases of historical leaks, primarily harvested by infostealer malware. Once an initial entry point was secured, the threat actors demonstrated the ability to pivot directly into internal Active Directory environments, establishing deep and persistent network access that could evade routine security scrutiny.
One particularly alarming technical aspect of the campaign involves the active interception of SSL VPN authentication hashes. These intercepted hashes are subsequently cracked offline using a dedicated 45-GPU cluster managed via Hashtopolis. This technique means that organizations relying solely on encrypted credentials are still at risk if their perimeter is breached. Post-breach, operators continuously monitor traversing network traffic to harvest additional login credentials, creating a self-perpetuating cycle of unauthorized access.
Global Impact and Confirmed Victims
The confirmed victims of the “FortiBleed” campaign span virtually every sector of the global economy. Diachenko’s research validated full network compromises within organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey. Critically, this includes a Turkish NATO defense contractor from which classified defense documents were successfully exfiltrated.
The attackers’ verified credential database contains credentials belonging to some of the world’s largest enterprises, including:
- Technology & Manufacturing: Foxconn, Samsung, Siemens, Lenovo, Oracle
- Professional Services: PwC, Accenture
- Telecommunications: Comcast
- Thousands of government entities and critical infrastructure providers.
A crucial insight from this dataset is that robust password complexity offered no defense against these attacks. A significant number of highly complex, 20-character passwords were successfully compromised, not through brute-force cracking from scratch, but because they already existed in plaintext within previously harvested infostealer databases.
This reality underscores a fundamental weakness: when credentials are stolen at the endpoint level before encryption is applied, no degree of complexity can protect them. This fundamentally challenges the efficacy of “strong password” policies as a primary perimeter defense strategy.
Hudson Rock has launched a dedicated online portal to allow organizations to verify if their domains are included in the compromised database.
What You Should Do
Organizations operating Fortinet devices must recognize “FortiBleed” as an immediate and critical threat. Prompt action is imperative:
- Force Credential Rotation: Immediately reset all Fortinet VPN and administrative interface passwords. The complexity of existing passwords is irrelevant if they have already been leaked.
- Enforce Universal MFA: Implement Multi-Factor Authentication (MFA) across all external gateways to neutralize the risk posed by stolen plaintext credentials.
- Audit Gateway Logs: Thoroughly review Fortinet access logs for any anomalous login locations, unexpected administrative sessions, or unusual traffic volumes.
- Restrict Management Interface Exposure: Apply stringent local-in policies to limit administrative panel access exclusively to trusted internal IP addresses. If not essential, disable FortiCloud SSO functionality.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.