Raleigh News Today

collapse
Home / Daily News Analysis / FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide

FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide

Jul 23, 2026  Twila Rosenbaum  4 views
FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide

A widespread credential-compromise campaign, dubbed FortiBleed, has exposed tens of thousands of Fortinet FortiGate firewalls around the world. Security researchers warn that attackers may have gained persistent, long-term access to enterprise networks by harvesting and cracking administrator passwords from stolen device configuration files.

The campaign first came to light when security researcher Volodymyr Diachenko posted on LinkedIn about discovering an attacker-controlled list containing potentially working FortiGate passwords, collected through various means. Shortly after, independent security firm SOCRadar identified an operational server belonging to an unnamed threat actor. That server held a trove of stolen FortiGate passwords, automation tools, victim lists, and other intelligence that pointed to a highly organized operation. While attribution remains ongoing, SOCRadar noted that the tooling and targeting patterns are consistent with Russian-speaking threat actors.

According to analyses by SOCRadar, Hudson Rock, and security researcher Kevin Beaumont, the attackers systematically collected configuration files from internet-facing Fortinet FortiGate firewalls. They then extracted password hashes from those files and used offline cracking tools to recover plaintext administrator credentials. The initial access vector—how the attackers first breached the firewalls to steal the config files—is still unknown, but it may involve exploiting known vulnerabilities in older or unpatched FortiOS versions. Fortinet has not publicly commented on the incident.

The scale of the breach is staggering. Although SOCRadar initially reported that the dataset contained working login credentials for over 30,791 devices, further analysis by Beaumont and Hudson Rock raised that number to approximately 75,000—roughly 50% of all internet-facing Fortinet firewalls indexed on Shodan. The compromised devices span 194 countries and more than 21,000 unique domains. The top three affected nations are India, the United States, and Mexico, which together account for nearly 12,000 compromised credentials. The dataset includes a mix of administrative and SSL VPN credentials, with a notable focus on organization-specific credentials, indicating deliberate targeting of enterprises.

The implications for affected organizations are severe. As Beaumont explained, attackers who gain administrative access to a FortiGate firewall can log in remotely, modify security policies, create backdoor user accounts, disable logging, and pivot to internal network resources. This essentially grants the adversary a foothold inside the perimeter, from which they can launch further attacks such as data exfiltration, ransomware deployment, or lateral movement. The long-term value of such access is high, as compromised firewalls are often overlooked during incident response unless credential rotation is enforced.

A critical factor in the success of this campaign is the age of the password hashing mechanisms used by many affected devices. Fortinet introduced PBKDF2-based password hashing for administrator credentials in FortiOS versions 7.2.11, 7.4.8, and 7.6.1. Prior to that, administrator passwords were stored using SHA-256 with salt, a much weaker algorithm that is far more susceptible to offline brute-force attacks. Compounding the problem, when an organization upgrades FortiOS to a version that supports PBKDF2, existing administrator passwords remain stored as SHA-256 hashes until each administrator successfully logs in at least once after the upgrade. This leaves a window of vulnerability that attackers can exploit if they have already obtained the configuration file. Arctic Wolf researchers highlighted this issue, noting that many organizations are unknowingly storing admin credentials using the older, weaker hashing mechanism even after upgrading.

To mitigate the risk, security experts urge all organizations using Fortinet firewalls to assume that any credentials contained in exposed configuration files have been compromised. Immediate steps include rotating all administrative and SSL VPN passwords, enforcing multi-factor authentication (MFA) for all admin accounts, and restricting internet access to management interfaces. Organizations should also review their FortiGate devices for signs of unauthorized access, such as unknown user accounts or policy changes. Upgrading to a supported FortiOS version that uses PBKDF2 is essential, but administrators must ensure that after the upgrade, every admin logs into the firewall at least once to trigger the re-hashing of their password. Alternatively, a super_admin account can manually update passwords to enforce the stronger encryption.

The FortiBleed campaign serves as a stark reminder that even after a vulnerability is patched, the data harvested during exploitation can retain its value for years. CEO of watchTowr Benjamin Harris noted that modern exploitation is often not about immediate impact, but about collecting data that can be used long after the initial breach is forgotten. Organizations must adopt a proactive stance: assume credentials will eventually be stolen, implement robust password policies, use hardware-backed two-factor authentication, and continuously monitor for signs of compromise. The firewalls themselves should not be treated as unbreachable boundaries; rather, they should be part of a layered defense strategy that includes network segmentation, endpoint detection, and regular security audits.

As the investigation continues, more details may emerge about the specific vulnerabilities exploited and the full extent of the data stolen. For now, the message from the security community is clear: any Fortinet firewall that has been exposed to the internet should be treated with suspicion. The password hashes stored in configuration files are a goldmine for attackers, and defending against such large-scale credential harvesting requires both technical measures and operational vigilance. The FortiBleed campaign underscores the need for vendors to adopt stronger default security practices and for organizations to prioritize credential hygiene at every level of their network infrastructure.


Source: Network World News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy