Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Sandworm Uses Fake Job Interviews to Distribute Trojanized WireGuard VPN
August 12, 2026
New Phishing Campaign Impersonates Google, Delivers Fake Audio Message
August 12, 2026
Best Business VPN Solutions for 2026
August 12, 2026
Home/CyberSecurity News/Critical Fortinet FortiGate SSL VPN RCE Vulnerability Exploited in Attacks
CyberSecurity News

Critical Fortinet FortiGate SSL VPN RCE Vulnerability Exploited in Attacks

Key Takeaways A vast cyber espionage operation, dubbed “FortiBleed,” has compromised over 73,932 Fortinet firewall URLs globally. The campaign, attributed to a Russian-speaking group,...

David kimber
David kimber
June 17, 2026 3 Min Read
60 0

Key Takeaways

  • A vast cyber espionage operation, dubbed “FortiBleed,” has compromised over 73,932 Fortinet firewall URLs globally.
  • The campaign, attributed to a Russian-speaking group, leverages stolen credentials from infostealer malware and targets FortiGate devices and SSL VPN gateways.
  • Attackers have gained deep, persistent access to internal Active Directory environments and exfiltrated sensitive data, including classified defense documents.
  • Password complexity offered no protection against compromise, as credentials were often stolen in plaintext before encryption.
  • Organizations are urged to implement immediate mitigation steps, including forced credential rotation and universal MFA.

“FortiBleed” Campaign Compromises Tens of Thousands of Fortinet Firewalls

A sophisticated cyber espionage campaign, now identified as “FortiBleed,” has stealthily infiltrated more than 73,932 unique Fortinet firewall URLs spanning 194 countries. This industrial-scale operation has targeted FortiGate devices and their associated SSL VPN gateways on an unprecedented global scale.

Table Of Content

  • Key Takeaways
  • “FortiBleed” Campaign Compromises Tens of Thousands of Fortinet Firewalls
  • Attack Modus Operandi and Scale
  • Global Impact and Confirmed Victims
  • What You Should Do

The extent of this widespread compromise was initially brought to light by security researcher Volodymyr “Bob” Diachenko, with subsequent in-depth analysis provided by Hudson Rock. Their findings reveal a highly automated attack infrastructure.

Attack Modus Operandi and Scale

Threat actors engaged in an estimated 1.16 billion credential-based login attempts against over 320,000 FortiGate targets. Concurrently, they executed an additional 2.1 billion brute-force attempts against more than 160,000 MSSQL servers, ultimately leading to the compromise of 21,632 distinct domains.

This extensive campaign is attributed to a multi-operator, Russian-speaking cybercriminal collective. Their methodology extends far beyond simple credential stuffing, indicating a highly organized and technically proficient group.

The attackers systematically scanned the internet for exposed Fortinet instances. These identified targets were then subjected to credential validation against vast databases of historical leaks, primarily harvested by infostealer malware. Once an initial entry point was secured, the threat actors demonstrated the ability to pivot directly into internal Active Directory environments, establishing deep and persistent network access that could evade routine security scrutiny.

One particularly alarming technical aspect of the campaign involves the active interception of SSL VPN authentication hashes. These intercepted hashes are subsequently cracked offline using a dedicated 45-GPU cluster managed via Hashtopolis. This technique means that organizations relying solely on encrypted credentials are still at risk if their perimeter is breached. Post-breach, operators continuously monitor traversing network traffic to harvest additional login credentials, creating a self-perpetuating cycle of unauthorized access.

Global Impact and Confirmed Victims

The confirmed victims of the “FortiBleed” campaign span virtually every sector of the global economy. Diachenko’s research validated full network compromises within organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey. Critically, this includes a Turkish NATO defense contractor from which classified defense documents were successfully exfiltrated.

The attackers’ verified credential database contains credentials belonging to some of the world’s largest enterprises, including:

  • Technology & Manufacturing: Foxconn, Samsung, Siemens, Lenovo, Oracle
  • Professional Services: PwC, Accenture
  • Telecommunications: Comcast
  • Thousands of government entities and critical infrastructure providers.

A crucial insight from this dataset is that robust password complexity offered no defense against these attacks. A significant number of highly complex, 20-character passwords were successfully compromised, not through brute-force cracking from scratch, but because they already existed in plaintext within previously harvested infostealer databases.

This reality underscores a fundamental weakness: when credentials are stolen at the endpoint level before encryption is applied, no degree of complexity can protect them. This fundamentally challenges the efficacy of “strong password” policies as a primary perimeter defense strategy.

Hudson Rock has launched a dedicated online portal to allow organizations to verify if their domains are included in the compromised database.

What You Should Do

Organizations operating Fortinet devices must recognize “FortiBleed” as an immediate and critical threat. Prompt action is imperative:

  • Force Credential Rotation: Immediately reset all Fortinet VPN and administrative interface passwords. The complexity of existing passwords is irrelevant if they have already been leaked.
  • Enforce Universal MFA: Implement Multi-Factor Authentication (MFA) across all external gateways to neutralize the risk posed by stolen plaintext credentials.
  • Audit Gateway Logs: Thoroughly review Fortinet access logs for any anomalous login locations, unexpected administrative sessions, or unusual traffic volumes.
  • Restrict Management Interface Exposure: Apply stringent local-in policies to limit administrative panel access exclusively to trusted internal IP addresses. If not essential, disable FortiCloud SSO functionality.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

FishMonger Hackers Deploy SprySOCKS Backdoor to Windows, Adding Stealth Features

Next Post

Fake macOS Software Updates Steal Passwords, Crypto Wallet Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft SharePoint Server CVE-2023-29357 Lets Attackers Remotely Execute Code
August 12, 2026
Critical Windows AFD.sys Zero-Day Exploited by Lazarus Group
August 12, 2026
Critical Microsoft Outlook RCE Vulnerability Patched
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us