Searching for FortiBleed, Fortinet firewall credentials leaked, or FortiGate hacked 2026? This article explains the June 2026 campaign that verified 75,000 working admin and SSL VPN credentials after targeting more than 320,000 FortiGate firewalls worldwide—and what network teams must do today.
Breaking — June 17, 2026: Security researchers disclosed a massive credential trove dubbed FortiBleed, exposing verified Fortinet FortiGate administrator and SSL VPN logins for organizations across 194 countries. BreachHistory tracks the incident at FortiBleed 2026.
What happened
Researcher Volodymyr “Bob” Diachenko discovered an exposed server containing what appeared to be valid FortiGate credentials—usernames, email addresses, and plaintext passwords—for thousands of enterprise firewalls. BleepingComputer reported June 17 that Hudson Rock analysis counted 73,932 unique firewall URLs impacting 21,632 domains.
Cybersecurity expert Kevin Beaumont independently verified portions of the data and told BleepingComputer: “I have been able to confirm the authenticity of some of the admin logins and passwords—this looks like a real dump.” In a follow-up analysis, Beaumont wrote the collection covers roughly 75,000 devices, most still online—representing about half of all internet-exposed Fortinet firewalls per Shodan network data.
Scale of the FortiBleed campaign
Diachenko’s review of attacker artifacts accidentally left on the same server described an industrialized operation:
- 320,777 FortiGate targets hit with approximately 1.16 billion credential attempts
- 163,650 Microsoft SQL Server systems targeted with an additional 2.1 billion brute-force attempts
- SSL VPN authentication hashes intercepted and cracked using a 45-GPU cluster managed via Hashtopolis
- Post-compromise pivoting into internal Active Directory environments for persistence
The attackers maintained detailed logs of successful compromises—formatting victim metadata by company type, revenue, and country in a pattern Beaumont associated with eCrime syndicates packaging initial access for dark-web sale.
Who was exposed
Diachenko’s screenshots and BleepingComputer reporting named major global enterprises in the dataset, including:
- Chevron, Samsung, Foxconn, Comcast, AT&T
- Mercedes-Benz, Toyota, Sinopec, State Grid
- Fortinet’s own appliances among affected instances
Hudson Rock published a free FortiBleed lookup tool so organizations can check whether their domains appear in the collection.
Why so many passwords were crackable
Beaumont explained that Fortinet hardened admin credential storage in early 2025 by moving to PBKDF2—but only for administrators who logged in again after applying firmware updates. Devices that never re-authenticated continued storing credentials in the older SHA-256 with salt format, making offline brute-force feasible once configuration exports were obtained.
Many exposed passwords were long and complex—suggesting attackers recovered them from exported configs or recycled credentials previously stolen by infostealer malware, not simple dictionary guessing alone.
How this differs from prior Fortinet leaks
Beaumont noted the affected IP addresses differ from the 2025 Belsen Group leak of 15,000 FortiGate configs tied to CVE-2022-40684. FortiBleed appears to be a more recent, larger collection with many devices running current FortiOS versions—indicating ongoing exposure of internet-facing management interfaces rather than a single historical zero-day alone.
What was not confirmed at initial reporting
- Fortinet had not published a vendor security advisory specifically naming FortiBleed at BleepingComputer’s June 17 reporting
- The exact initial intrusion vector for configuration theft remains unclear—prior CVEs, misconfiguration, or a new flaw were all under investigation
- Per-organization notification counts were not uniformly published by victims at disclosure time
Action items for FortiGate administrators
- Rotate every admin and SSL VPN password immediately—treat all gateway credentials as compromised until proven otherwise.
- Enforce MFA on all external admin interfaces and SSL VPN portals.
- Upgrade FortiOS to the latest release and have every administrator log in again to force PBKDF2 credential re-hashing.
- Remove internet exposure of FortiGate management interfaces where possible; use out-of-band access instead.
- Audit gateway logs for successful admin logins from unexpected IPs; if backdoor users or altered policies appear, consider device replacement.
- Check the Hudson Rock lookup tool and monitor employee credentials against threat-intelligence feeds.
- Hunt in Active Directory for lateral movement if perimeter credentials were valid—attackers in this campaign pivoted internally after VPN access.
Why FortiBleed matters for enterprise security
Firewalls sit at the perimeter of nearly every enterprise network. Verified admin credentials are not a “maybe”—they are live keys to VPN tunnels, policy changes, and downstream domain compromise. FortiBleed demonstrates that exposed management planes + crackable credential storage + automated brute force can compromise a meaningful fraction of the global Fortinet install base in weeks, not years.
Related searches
- FortiBleed Fortinet credentials
- FortiGate admin password leaked 2026
- Fortinet SSL VPN breach June 2026
- How many Fortinet firewalls were hacked
- FortiBleed lookup tool Hudson Rock
- Fortinet breach history on BreachHistory
FAQ
What is FortiBleed?
A June 2026 exposed credential collection of verified FortiGate admin and SSL VPN logins, named by researchers after Diachenko’s discovery and Hudson Rock’s analysis.
How many devices were compromised?
About 75,000 verified credential pairs across 73,932 unique firewall URLs; attackers targeted 320,000+ FortiGate instances in the broader campaign.
Did Fortinet confirm the breach?
Researchers and BleepingComputer attested the credential dump’s authenticity; Fortinet had not issued a matching vendor incident notice at initial reporting.
Am I affected?
Use Hudson Rock’s FortiBleed lookup and rotate credentials if your domain or appliance URL appears.
Canonical incident record: FortiBleed 2026 on BreachHistory.
Sources: BleepingComputer, Kevin Beaumont / DoublePulsar, Hudson Rock lookup tool
Updated 2026-06-19.