Vulnerabilities

FortiBleed Leak Exposes 73,000 Fortinet VPN Credentials

June 17, 2026 16:02 · 12 min read
FortiBleed Leak Exposes 73,000 Fortinet VPN Credentials

Introduction to FortiBleed Leak

A newly discovered data leak, dubbed 'FortiBleed', has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. The exposed data was first discovered by security researcher Bob Diachenko, who found a server containing valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords.

Exposure of Sensitive Data

According to screenshots and information shared by Diachenko, the database contains entries for major organizations such as Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and many others. The exposed data also included comments listing each organization's industry, revenue, and number of employees, likely for planning attacks.

Diachenko later shared additional information that claimed the operation was conducted by a Russian-speaking multi-operator threat group that harvested credentials for FortiGate SSL VPN devices. The attackers allegedly conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets and an additional 2.1 billion attempts against 163,650 Microsoft SQL Server systems.

Method of Attack

Diachenko told BleepingComputer that he obtained these details after analyzing additional files inadvertently exposed on the same server. The researcher explained that the attackers intercepted SSL VPN authentication hashes, cracked them using a 45-GPU cluster managed through Hashtopolis, and used the recovered credentials to move laterally into internal Active Directory environments.

Multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly stolen. Threat intelligence company Hudson Rock has since published its own analysis of the exposed data after receiving the dataset from Diachenko.

Hudson Rock Analysis

According to Hudson Rock, the dataset contains 73,932 unique firewall URLs across 194 countries and impacts 21,632 unique domains. The company says the attackers maintained detailed logs of successful compromises and assembled a database containing verified credentials for organizations across nearly every major industry sector.

Among the organizations Hudson Rock says appear in the dataset are Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators. The company also released statistics showing that the highest number of affected devices was in India, the United States, Taiwan, Mexico, Turkey, Thailand, Colombia, Malaysia, Chile, and the United Arab Emirates.

Authenticity of Credentials

Cybersecurity researcher Kevin Beaumont independently reviewed portions of the exposed data and told BleepingComputer that some of the credentials are authentic. Beaumont published additional findings indicating that the dataset contains credentials for roughly 75,000 Fortinet devices, most of which remain online.

According to Beaumont, the data appears to have originated from exported Fortinet configurations because it contains information, including email addresses, that is typically only accessible through configs. He also said the affected IP addresses are different from those in the 2025 Belsen Group Fortinet leak, further indicating that this is a more recent and larger collection of compromised devices.

Recommendations for Affected Organizations

Organizations in the dataset should immediately rotate passwords associated with Fortinet VPN and administrative interfaces, enforce MFA, examine gateway logs for suspicious activity, and monitor for exposed employee credentials. Hudson Rock has created a free FortiBleed lookup tool to check if your organization is impacted.

BleepingComputer contacted Fortinet regarding the exposed dataset and will update this article if we receive a response. In the meantime, security teams are advised to test every layer before attackers do, as 54% of successful attacks are logged and only 14% are alerted on.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free