Vulnerabilities

FortiBleed Leak: 74,000 Fortinet Credentials Exposed

June 19, 2026 12:10 · 12 min read
FortiBleed Leak: 74,000 Fortinet Credentials Exposed

FortiBleed Leak: A Massive Exposure of Fortinet Credentials

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged Fortinet customers to secure their devices after a massive data leak, dubbed FortiBleed, exposed nearly 74,000 firewall and VPN credentials. This warning comes after threat actors used compromised credentials to target internet-accessible Fortinet devices across government and private-sector organizations worldwide.

According to CISA, FortiBleed involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways. The agency has called on affected FortiGate appliance owners to take immediate action to secure their devices.

Recommended Actions

CISA also advised Fortinet customers to store admin credentials using the modern Password-Based Key Derivation Function 2 (PBKDF2) hashing algorithm and to restrict firewall management interfaces from public internet access. Additionally, removing any unauthorized accounts can help reduce the attack surface as much as possible.

The FortiBleed Data Leak

The FortiBleed data leak was uncovered by security researcher Volodymyr Bob Diachenko, who discovered a server containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for 73,932 firewall URLs worldwide. The exposed data also includes each organization's industry, revenue, and employee count, which Diachenko said appeared to be compiled to assist in planning future attacks.

Threat intelligence company Hudson Rock, which analyzed the dataset, described it as one of the largest known collections of compromised Fortinet credentials, spanning 21,632 unique domains and 194 countries. The dataset includes organizations such as Samsung, Mercedes-Benz, Foxconn, Chevron, Comcast, AT&T, and Toyota, along with many government agencies and critical infrastructure operators.

Affected Organizations and Countries

The highest number of affected devices were from India, the United States, Taiwan, Mexico, Turkey, Thailand, Colombia, Malaysia, Chile, and the United Arab Emirates. The leak has significant implications for the security of these organizations and their customers.

Link to Russian-Speaking Threat Group

Diachenko also said that the operation was conducted by a Russian-speaking threat group that allegedly carried out approximately 1.16 billion credential attempts against more than 320,000 FortiGate targets to intercept SSL VPN authentication hashes. The source of the configuration data remains unknown.

Cybersecurity expert Kevin Beaumont has independently confirmed the authenticity of some credentials and noted that most affected devices remain online. The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data, Beaumont said, adding that the leaked data appears to have originated from Fortinet configuration files.

Free FortiBleed Lookup Tool

Hudson Rock has created a free FortiBleed lookup tool to help organizations check whether they are affected. This tool can be used to determine if an organization's credentials have been exposed in the leak.

Related Vulnerabilities and Exploits

On Monday, threat intelligence company Defused reported that several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform are now exploited in attacks. In total, CISA tracks 26 Fortinet security flaws that have been exploited in the wild in recent years, 13 of which were abused in ransomware attacks.

Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper to learn more about protecting your organization from cyber threats.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free