# CISA Warns of FortiBleed Campaign: 86,644 Fortinet Firewalls Compromised via Default Credentials
## Introduction
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on June 19, 2026, alerting organizations worldwide that tens of thousands of Fortinet FortiGate appliances have been actively compromised in a sprawling credential-stuffing campaign dubbed FortiBleed. The attack, attributed to Russian-speaking threat actors, has compromised 86,644 devices through a self-sustaining two-stage methodology that exploits widespread failures in credential hygiene across the globe's largest enterprises. The campaign underscores a troubling reality: even in 2026, organizations continue to operate with default and unchanged factory credentials on critical internet-facing security infrastructure.
---
## The Threat: FortiBleed Explained
FortiBleed represents a large-scale, highly automated attack targeting internet-exposed Fortinet FortiGate firewalls and VPN gateways. The threat actors behind the campaign employ a methodical approach:
Stage One: Initial Access via Credential Spray
Stage Two: Credential Harvesting and Proliferation
According to Hudson Rock, a threat intelligence firm tracking the campaign, "the threat actors have built a verified database of working credentials for some of the largest enterprises on the planet."
---
## Background and Context: Why This Happens in 2026
### The Credential Breakdown
SOCRadar's analysis of compromised credentials reveals a damning picture of organizational security practices:
| Credential Type | Percentage | Significance |
|---|---|---|
| Generic admin accounts | 35% | Factory defaults never changed |
| Built-in Fortinet system accounts | 28.3% | System-generated accounts not rotated |
| Organization-specific accounts | 36.7% | Custom accounts, likely from prior breaches or weak practices |
The prevalence of default and system-level accounts demonstrates widespread failure across organizations to implement basic credential hygiene—renaming default accounts and rotating factory credentials.
The presence of org-specific accounts as the largest category is particularly alarming. It suggests that threat actors are not simply harvesting publicly known default credentials, but are successfully leveraging credentials from prior breaches where victims never rotated passwords following disclosure.
### Geographic and Sectoral Impact
As of June 19, 2026, FortiBleed has impacted organizations across multiple continents:
Most Impacted Sectors:
Geographic Distribution:
This global spread reflects the internet-facing nature of the targeted devices. Many organizations deploy FortiGate appliances at network edges for remote access and VPN connectivity—making them inherently exposed to internet-based scanning and attack campaigns.
---
## Technical Details: Why Older Devices Remain Vulnerable
### The Password Hashing Gap
A critical technical factor enables FortiBleed's success: legacy password hashing mechanisms still in use across many FortiGate installations.
According to Arctic Wolf's analysis:
The U.K. National Cyber Security Centre (NCSC) suspects that threat actors may have exploited knowledge of Fortinet's legacy credential storage mechanisms and older hashing implementations. The combination of weak hashing and unchanged default credentials creates an ideal attack surface.
### Attack Mechanics
The attack tool custom-built by the threat actors:
1. Performs mass internet scanning to identify Fortinet login endpoints
2. Leverages a curated list of leaked Fortinet credentials and known defaults
3. Automates credential testing across identified targets
4. Stores confirmed valid credentials in a verified database
5. Uses harvested credentials to cascade attacks across additional devices
---
## Scope and Impact: "Nearly Every Sector"
According to Hudson Rock, "the scale of this breach touches nearly every sector of the global economy, sparing no industry." With 86,644 confirmed compromised devices, the FortiBleed campaign represents one of the largest known coordinated attacks on internet-facing security infrastructure.
The threat landscape is particularly concerning because:
---
## Implications: From Firewall to Full Compromise
A compromised FortiGate appliance is not merely a "firewall breach"—it is a network visibility and control point for attackers. Once inside:
For organizations in sensitive sectors—telecom, government, and education—a compromised firewall could enable espionage, infrastructure manipulation, or data exfiltration at scale.
---
## Recommendations: Immediate and Long-Term Actions
### CISA's Immediate Guidance
CISA has outlined the following critical steps for FortiGate customers:
Immediate Actions (within 24-48 hours):
Short-Term Hardening (within 1-2 weeks):
Long-Term Resilience (ongoing):
---
## HackWire Analysis: Default Credentials in 2026 Are Still a Mass Casualty Event
Here's what stands out about FortiBleed: we are in 2026, and 86,644 organizations worldwide have failed to change default credentials on their firewalls. This isn't a zero-day exploit or an advanced persistent threat requiring nation-state resources. This is brute-force credential stuffing succeeding at massive scale because organizations have not implemented basic security hygiene.
The credential breakdown is the real story. Organization-specific accounts representing 36.7% of compromises tells us that prior breaches are directly enabling current ones. When Fortinet leaks occur, or when credentials are exposed in other breaches, organizations are not rotating them. They're not treating compromised credentials as signals to harden their infrastructure. Instead, they're leaving those credentials sitting dormant until threat actors harvest them and use them again.
The self-sustaining nature of this attack—where each compromise yields credentials to compromise more targets—is particularly damning for the software supply chain. When your firewall is compromised, every customer leveraging similar security postures becomes a target. Fortinet's advice to "follow best practices" is technically correct but functionally useless. Organizations clearly cannot implement basic practices on their own. This points to a systemic failure: either the tooling for credential management is inadequate, or organizations lack the operational discipline to use it.
For defenders, the pattern is clear: treat any Fortinet installation as potentially compromised until proven otherwise. Review logs from the first day of 2026 forward. Assume that if your appliances were exposed and running default or weakly rotated credentials, they've been inside your network for months. The threat actors have a verified database of your credentials. Assume lateral movement. Assume persistence. Act accordingly.
— *HackWire Editorial*
---
## Related Coverage