FortiBleed: 75,000 Fortinet Firewalls Compromised in Massive Global Credential Theft Campaign
A sweeping cyber espionage campaign has compromised around 75,000 Fortinet firewall and VPN devices across 194 countries, exposing credentials from Fortune 500 firms, government agencies, and critical infrastructure providers worldwide.

Dark server room with glowing blue network hardware and a world map showing global cyber threat hotspots
A large-scale cyber espionage campaign has compromised approximately 75,000 Fortinet firewall and VPN devices across 194 countries, exposing credentials belonging to some of the world's largest enterprises, government agencies, and critical infrastructure operators.
First identified by security researcher Volodymyr "Bob" Diachenko and further analyzed by cybersecurity firm Hudson Rock and researcher Kevin Beaumont, the campaign, now dubbed "FortiBleed" represents one of the most significant perimeter security breaches in recent memory.
Scale and Scope
Hudson Rock's analysis identified 73,932 unique firewall URLs and 21,632 unique affected domains in the leaked dataset. According to device search engine Shodan, this figure represents roughly 50% of all internet-facing Fortinet firewall devices globally.
The most heavily impacted countries by number of breached devices include India (9,629), the United States (6,352), Taiwan (3,637), Mexico (3,197), and Turkey (3,032). The United Arab Emirates ranked tenth with 1,988 compromised devices. Every major sector of the global economy was affected, with IT services, telecommunications, financial services, government, and healthcare among the hardest-hit industries.
Among the verified victims are major multinational corporations including Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, and Oracle, alongside numerous government entities and critical infrastructure providers.
Attacker Methodology
The campaign is attributed to a multi-operator, Russian-speaking cybercriminal group based on Russian-language instructions embedded in discovered scripts. The operation's scale is extraordinary: attackers executed an estimated 1.16 billion credential attempts against over 320,000 FortiGate targets, along with 2.1 billion brute-force attempts directed at over 160,000 MSSQL servers.
The group's methodology involved intercepting SSL VPN authentication hashes and cracking them offline using a dedicated 45-GPU cluster managed via Hashtopolis. The data is believed to originate from device configuration exports, allowing credentials to be extracted and cracked without ever triggering active defenses on the targeted devices.
Once inside, operators systematically pivoted into internal Active Directory environments to establish deep network persistence. Diachenko confirmed full network compromises at multiple organisations across Japan, Taiwan, Vietnam, Iraq, and Turkey. Most critically, a Turkish NATO defense contractor was among the victims, with classified defense documents reportedly exfiltrated.
This approach goes beyond simple credential reuse. As Hudson Rock noted, the attackers built a structured, categorised database of working credentials, organized by company type, revenue, and country, a hallmark of eCrime syndicates packaging initial access for sale on dark web marketplaces.
Why Complex Passwords Did Not Help
One of the more alarming findings from the FortiBleed dataset is the high volume of highly complex passwords that were successfully compromised. Password complexity policies, a cornerstone of most enterprise security frameworks, offered no protection here.
When credentials are recovered in plaintext via infostealers or extracted from configuration files, a 20-character complex string is no more secure than a simple one. This underscores the growing importance of credential intelligence monitoring as a proactive security layer.
A key technical factor also contributed to the breach's success. While Fortinet hardened admin credential storage in early 2025 by transitioning to PBKDF2 hashing, this protection only applied if administrators actively logged in after applying the firmware update. Many devices continued storing credentials in the older, more vulnerable SHA-256 with salt format, leaving them susceptible to offline brute-forcing once configuration files were extracted.
Fortinet's Response
Fortinet acknowledged awareness of the campaign but pushed back on characterisations of it as a novel breach. A company spokesperson stated that the data involved is "a resharing of data from previous incidents, as well as bruteforcing of credentials, and is not related to any recent incident or advisory." The company added that organisations following routine best practices, including regularly rotating credentials, face minimal risk.
Security researchers largely contested this framing. Beaumont noted that many of the compromised devices are running recent firmware patches, and that most remain online and exposed.
Immediate Mitigation Steps
- Organisations running Fortinet firewall or VPN infrastructure should act immediately:
- Remove internet exposure - Ensure the FortiOS Management Interface is not publicly accessible unless absolutely necessary.
- Force credential rotation and re-hash passwords - Upgrade to the latest FortiOS release and have all administrators log back in to trigger re-hashing under the more secure PBKDF2 standard.
- Assume compromise - If any suspect successful logins to admin accounts are observed, treat the device as compromised. Attackers may have altered security controls or created backdoor users. In severe cases, replacing the device entirely may be warranted.
- Enforce MFA universally - Multi-Factor Authentication on all external gateways and admin interfaces neutralises stolen plaintext credentials as an attack vector.
- Monitor for stolen credentials - Proactively check employee and vendor credentials against threat intelligence databases. Hudson Rock has launched a free domain lookup tool allowing organisations to verify whether their domains appear in the compromised dataset.
For organisations operating in the GCC and MENA region, this campaign is a direct call to audit perimeter device exposure. The UAE's inclusion in the top ten affected countries highlights the regional risk. For context on how regional organisations are approaching network perimeter security, visit MENA Cyberwire
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.