FortiBleed: 86,000 Firewalls, One Legacy Hash

A security researcher stumbles on an exposed server at 3 AM. Inside: a searchable database of verified admin credentials for 86,644 Fortinet FortiGate firewalls, organized by country, industry, and annual revenue. The attackers didn't just steal passwords — they built a shopping catalog for breaking into enterprise networks worldwide.
This is FortiBleed, and it may be the most consequential perimeter device compromise of 2026.
How FortiBleed Was Discovered
On June 13, 2026, security researcher Volodymyr "Bob" Diachenko found an exposed threat actor server hosting a growing database of validated credentials alongside automated attack tooling. Within 48 hours, six independent security firms — Recorded Future, Arctic Wolf, Bitsight, Field Effect, SOCRadar, and Hudson Rock — independently validated portions of the dataset.
The initial count was 73,932 compromised devices. By June 19, that number climbed to 86,644 unique FortiGate firewalls across 194 countries. Researchers estimate roughly half of all internet-facing FortiGate devices are affected.
The victim list reads like a Fortune 500 directory: Samsung, Siemens, Oracle, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, DHL, and Fortinet itself. A Turkish NATO defense contractor confirmed exfiltration of classified defense documents.
The Three-Phase Attack Pipeline
FortiBleed wasn't a single exploit. It was an industrialized credential supply chain operating in three distinct phases.
Phase 1: Mass Reconnaissance
The group deployed automated scanners across 59.3 million internet hosts, hunting for exposed Fortinet management interfaces, FortiGate SSL VPN login portals, and Microsoft SQL Server instances. They fingerprinted approximately 437,000 FortiGate devices during this sweep.
Cybersecurity enthusiast focused on ethical hacking, penetration testing, bug bounty hunting, and security education. Founder of CyberBlockz, sharing practical cybersecurity knowledge, CTF challenges, and hands-on training to help learners develop real-world security skills and stay updated with the latest threats and vulnerabilities.




