FortiBleed Escalates: 110 Million Credentials Harvested Across 430,000 FortiGate Devices
New intelligence from SOCRadar, SpyCloud, and Zenox confirms the FortiBleed campaign has now harvested over 110 million credentials from more than 430,000 FortiGate devices globally. The operation runs 659 active credential-harvesting pipelines. GCC enterprises must act immediately.

A Fortinet firewall appliance in a corporate data centre rack, representing the escalating FortiBleed credential harvesting campaign that has now confirmed 110 million stolen credentials across over 430,000 compromised FortiGate devices globally
The FortiBleed credential harvesting campaign has escalated significantly beyond previously reported figures. New technical intelligence published by SOCRadar on 23 June 2026 confirms that Russian-speaking threat actors behind the operation have now compromised more than 430,000 FortiGate firewall and SSL VPN devices globally, harvesting over 110 million credentials in the process. Earlier reporting had placed the device compromise count at 86,644 as of 19 June 2026. The new figures represent a confirmation that the campaign is active, ongoing, and materially larger than the initial disclosure.
The campaign has been running since at least February 2026, and in its latest documented state is operating 659 simultaneous credential-harvesting pipelines. According to data captured by SpyCloud, the FortiGate-specific capture cycle began on 19 May 2026, with the hash-cracking infrastructure set up towards the end of that month. Zenox, a Brazilian cybersecurity firm that analysed the threat actors' open operational servers directly, confirmed that each pipeline cycle runs for 300 minutes with status checks every minute, and that successful credential validation rates hovered near 90 per cent in the early cycles.
The Full Scale of What Has Been Captured
The 110 million credentials confirmed by SOCRadar break down as follows: 14.8 million Remote Authentication Dial-In User Service (RADIUS) credentials, 924,000 NTLM hashes, 130,000 Kerberos hashes, and 89 million MySQL authentication tokens. The scale of MySQL token capture is particularly striking and suggests that attackers are not limiting their interest to network access credentials but are actively targeting database authentication that could provide lateral access to application and data tiers within compromised environments.
At the heart of the operation is a Golang-based tool called FortigateSniffer, which exploits a native FortiOS diagnostic command to passively capture authentication traffic from compromised appliances. The intrusion phase itself leaves a heavy footprint: attackers gained administrative control through SSH brute-force attacks and credential stuffing, generating substantial authentication log activity during the initial access stage. Once inside, FortigateSniffer operates silently, monitoring traffic across 24 protocols including TACACS+, Kerberos, RPC, SMB, LDAP, SMTP, FTP, Telnet, RDP, WinRM, MS-SQL, MySQL, PostgreSQL, and RADIUS. Because the sniffer uses the device's own built-in diagnostic function for passive packet capture, the ongoing harvesting activity does not generate anomalous traffic patterns that would be flagged by standard intrusion detection systems. The intrusion leaves traces. The harvesting does not.
After capture, the harvested hashes are cracked using Hashmat and Hashtopolis, orchestrated through a Telegram bot named HASHBOT. Cracked credentials are then used for Active Directory enumeration and lateral movement, and sensitive data from network shares is exfiltrated while stolen session cookies maintain persistent access.
The campaign's scope is also broader than FortiGate alone. SOCRadar confirmed that FortiBleed is part of a wider multi-vendor initial access operation that simultaneously targets Synology NAS devices, Sophos firewalls, RDWeb portals, Citrix SSL VPNs, and MS-SQL servers using automated brute-force techniques active since 28 February 2026.
The GCC Exposure
Fortinet FortiGate devices are among the most widely deployed network security appliances across GCC enterprises, government entities, financial institutions, and critical infrastructure operators. The prevalence of default credentials and unconfigured administrative accounts is the primary vulnerability being exploited. SOCRadar noted that generic admin accounts represent 35 per cent of compromised credentials, and built-in Fortinet system accounts account for a further 28.3 per cent, meaning that over 63 per cent of breached devices were compromised through credentials that should have been rotated or removed during initial deployment.
A separate threat actor operating under the name SantaAd has been advertising access to thousands of Fortinet devices on criminal forums, with starting prices of $30,000 rising to $60,000 within hours of initial listings. Whether SantaAd is directly pulling from the FortiBleed credential cache or running a parallel operation remains unconfirmed, but it underscores the aggressive monetisation of edge-device vulnerabilities by Initial Access Brokers operating in this space.
The operational intelligence gathered from FortiBleed-compromised devices includes network topology, Active Directory structure, and privileged account credentials. Any organisation whose FortiGate appliance was accessible from the internet during the period February to June 2026 and which had not rotated default credentials and enforced MFA should assume they are in the compromised set until proven otherwise. For enterprises running Microsoft Azure environments alongside Fortinet perimeter infrastructure, the lateral movement risk is compounded: cracked NTLM and Kerberos credentials can be used to move directly into Azure Active Directory and cloud-hosted workloads if identity boundaries between on-premises and cloud environments are not enforced.
Mandatory Remediation Steps
CISA, Fortinet, and multiple security firms have now issued guidance. For GCC enterprises the minimum required actions are to terminate all active administrator and VPN sessions and reset all credentials immediately, implement multi-factor authentication across all administrative access, and upgrade to FortiOS versions 7.4, 7.6, or 8.0.
A critical nuance on the upgrade path: upgrading to FortiOS versions that support PBKDF2 password hashing only protects accounts if administrators actively rotate their passwords after the upgrade. Legacy SHA-256 hashes remain present in backward-compatible configuration fields, and attackers are actively pulling and cracking those hashes. Credential rotation is not optional after patching. It is the point of patching.
Organisations should also review all firewall and VPN user accounts for unauthorised changes, and audit all administrative access logs for unexpected IP addresses and lateral movement indicators from the period beginning 28 February 2026.
For Kuwait-based organisations, the Kuwait NCSC National Basic Cybersecurity Controls mandate issued earlier this year specifically requires mandatory credential governance controls and MFA enforcement across network infrastructure. FortiBleed-class campaigns represent precisely the threat scenario those controls were designed to address, and non-compliant organisations facing active exposure from this campaign carry both a security and a regulatory liability.
For organisations running Sophos, Synology NAS, or Citrix infrastructure alongside Fortinet: FortiBleed's scope includes all of those platforms. Remediation cannot be limited to Fortinet appliances alone if the broader network estate is affected.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.