2026 FortiBleed — 75K FortiGate admin/SSL VPN credentials verified; 320K devices targeted
Data compromised
Verified admin and SSL VPN usernames, emails, and plaintext passwords for 73,932 unique firewall URLs across 21,632 domains in 194 countries
Technical writeup
In mid-June 2026, security researcher Volodymyr “Bob” Diachenko discovered an exposed server holding what appeared to be working Fortinet FortiGate credentials. BleepingComputer reported June 17 that the collection dubbed “FortiBleed” contains 73,932 unique firewall URLs with verified admin and SSL VPN logins across 21,632 domains in 194 countries—names including Chevron, Samsung, Comcast, AT&T, Mercedes-Benz, and Toyota per Diachenko’s screenshots. Kevin Beaumont independently confirmed authenticity of some admin passwords and estimated roughly 75,000 affected devices—about half of internet-exposed Fortinet firewalls per Shodan analysis—with most still online and running recent FortiOS builds. Follow-up SOCRadar research tied the operation to INC and Lynx ransomware affiliates, reporting access to both groups’ negotiation panels, 200+ operational servers, and overlap between FortiBleed victim data and later INC leak-site listings; BleepingComputer covered the Lynx/INC linkage July 1, 2026. Diachenko’s analysis described ~1.16 billion credential attempts against 320,777 FortiGate targets, SSL VPN hash interception cracked on a 45-GPU Hashtopulus cluster, and a custom “FortiGate Sniffer” packet-capture tool on compromised appliances. Beaumont noted many devices still stored admin credentials in pre-2025 SHA-256-with-salt format unless admins re-logged in after PBKDF2 firmware hardening. Fortinet had not published a matching vendor incident notice at initial trade-press reporting; BreachHistory indexes 75,000 verified credential pairs per researcher and Hudson Rock attestation.
Root cause
Internet-wide FortiGate brute-force and SSL VPN hash-cracking campaign; exposed management interfaces and legacy SHA-256 credential storage
References
- https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/
- https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/
- https://www.bleepingcomputer.com/news/security/fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials/
- https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/
- https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8
- https://www.hudsonrock.com/fortinet