FortiGate Compromise Becomes a Resale Pipeline

A FortiGate breach now means more than edge access. The firewall can be turned into a credential collection point, and the real damage is downstream: passwords, hashes, and session cookies can be cracked, reused, and sold into Active Directory and customer environments even after the appliance is cleaned. SOCRadar says FortiBleed has targeted more than 430,000 FortiGate devices worldwide since at least February and has already exposed more than 110 million credentials. The operation is being run as a financially motivated initial-access-broker campaign, with FortigateSniffer using FortiOS diagnostics to passively capture authentication traffic, and with rented GPU cracking and automated Telegram-controlled pipelines turning that access into resale-ready logins. The campaign now looks broader than a Fortinet-only event. It reaches into MSP and IT-services networks, where one compromised firewall can become an access path into many downstream victims, and it also extends across other vendors, which makes perimeter-only cleanup too narrow a response.

Part of the PlainSec briefing for 2026-06-25

Sources