Threats · 82 days ago
A FortiGate breach now means more than edge access. The firewall can be turned into a credential collection point, and the real damage is downstream: passwords, hashes, and session cookies can be cracked, reused, and sold into Active Directory and customer environments even after the appliance is cleaned.
SOCRadar says FortiBleed has targeted more than 430,000 FortiGate devices worldwide since at least February and has already exposed more than 110 million credentials. The operation is being run as a financially motivated initial-access-broker campaign, with FortigateSniffer using FortiOS diagnostics to passively capture authentication traffic, and with rented GPU cracking and automated Telegram-controlled pipelines turning that access into resale-ready logins.
The campaign now looks broader than a Fortinet-only event. It reaches into MSP and IT-services networks, where one compromised firewall can become an access path into many downstream victims, and it also extends across other vendors, which makes perimeter-only cleanup too narrow a response.
6 sources covering this story
Risky Bulletin: FortiBleed hacks involved a lot of traffic sniffing
The FortiBleed hacks are worse than a credentials leak, a new White House executive order sets out a hard 2031 post quantum cryptography d [Read More
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
FortiBleed targeted 430,000 FortiGate firewalls with sniffers and brute-force pipelines that identified over 110 million credentials.
What the Fortibleed campaign means for organizations running FortiGate firewalls - Help Net Security
Analysts have pieced together the full attack chain from the FortiBleed leak, revealing a sophisticated, highly automated pipeline.
FortiBleed Attackers Turn Firewalls Into Credentials Stealers
The threat actors used a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign.
Russian Initial Access Broker Behind FortiBleed Campaign
Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.
FortiBleed campaign used custom FortiGate sniffer to steal credentials
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials.
Part of the PlainSec briefing for 2026-06-25