# CISA Warns of FortiBleed Campaign: 86,644 Fortinet Firewalls Compromised via Default Credentials


## Introduction


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on June 19, 2026, alerting organizations worldwide that tens of thousands of Fortinet FortiGate appliances have been actively compromised in a sprawling credential-stuffing campaign dubbed FortiBleed. The attack, attributed to Russian-speaking threat actors, has compromised 86,644 devices through a self-sustaining two-stage methodology that exploits widespread failures in credential hygiene across the globe's largest enterprises. The campaign underscores a troubling reality: even in 2026, organizations continue to operate with default and unchanged factory credentials on critical internet-facing security infrastructure.


---


## The Threat: FortiBleed Explained


FortiBleed represents a large-scale, highly automated attack targeting internet-exposed Fortinet FortiGate firewalls and VPN gateways. The threat actors behind the campaign employ a methodical approach:


Stage One: Initial Access via Credential Spray

  • Threat actors mass-scan the internet to identify Fortinet remote login endpoints
  • They deploy a custom brute-force tool to spray known credential combinations against identified devices
  • The attack leverages leaked Fortinet credentials and common default username-password pairs
  • Once access is obtained, the attackers establish a foothold on the compromised appliance

  • Stage Two: Credential Harvesting and Proliferation

  • Rather than immediately pivoting to deeper network access, attackers passively monitor traffic flowing through the compromised firewall
  • They extract additional credentials visible in network flows
  • These newly harvested credentials are verified and added to an ever-growing database of confirmed, working logins
  • This verified database becomes the source material for attacking additional targets, creating a self-sustaining cycle

  • According to Hudson Rock, a threat intelligence firm tracking the campaign, "the threat actors have built a verified database of working credentials for some of the largest enterprises on the planet."


    ---


    ## Background and Context: Why This Happens in 2026


    ### The Credential Breakdown


    SOCRadar's analysis of compromised credentials reveals a damning picture of organizational security practices:


    | Credential Type | Percentage | Significance |

    |---|---|---|

    | Generic admin accounts | 35% | Factory defaults never changed |

    | Built-in Fortinet system accounts | 28.3% | System-generated accounts not rotated |

    | Organization-specific accounts | 36.7% | Custom accounts, likely from prior breaches or weak practices |


    The prevalence of default and system-level accounts demonstrates widespread failure across organizations to implement basic credential hygiene—renaming default accounts and rotating factory credentials.


    The presence of org-specific accounts as the largest category is particularly alarming. It suggests that threat actors are not simply harvesting publicly known default credentials, but are successfully leveraging credentials from prior breaches where victims never rotated passwords following disclosure.


    ### Geographic and Sectoral Impact


    As of June 19, 2026, FortiBleed has impacted organizations across multiple continents:


    Most Impacted Sectors:

  • Telecom (highest exposure)
  • Government agencies
  • Education institutions

  • Geographic Distribution:

  • India (highest concentration)
  • United States
  • Mexico
  • Colombia
  • Thailand

  • This global spread reflects the internet-facing nature of the targeted devices. Many organizations deploy FortiGate appliances at network edges for remote access and VPN connectivity—making them inherently exposed to internet-based scanning and attack campaigns.


    ---


    ## Technical Details: Why Older Devices Remain Vulnerable


    ### The Password Hashing Gap


    A critical technical factor enables FortiBleed's success: legacy password hashing mechanisms still in use across many FortiGate installations.


    According to Arctic Wolf's analysis:


  • Fortinet upgraded its password hashing in FortiOS versions 7.2.11, 7.4.8, and 7.6.1, introducing PBKDF2-based hashing
  • The legacy system used SHA-256 with salt, which is cryptographically weaker and more susceptible to offline cracking
  • Organizations that upgrade from older versions retain SHA-256 hashes for administrator credentials—the hashes remain unchanged until the administrator successfully logs in after the upgrade
  • This creates a persistent vulnerability window, where large numbers of organizations continue storing sensitive credentials using outdated hashing mechanisms

  • The U.K. National Cyber Security Centre (NCSC) suspects that threat actors may have exploited knowledge of Fortinet's legacy credential storage mechanisms and older hashing implementations. The combination of weak hashing and unchanged default credentials creates an ideal attack surface.


    ### Attack Mechanics


    The attack tool custom-built by the threat actors:


    1. Performs mass internet scanning to identify Fortinet login endpoints

    2. Leverages a curated list of leaked Fortinet credentials and known defaults

    3. Automates credential testing across identified targets

    4. Stores confirmed valid credentials in a verified database

    5. Uses harvested credentials to cascade attacks across additional devices


    ---


    ## Scope and Impact: "Nearly Every Sector"


    According to Hudson Rock, "the scale of this breach touches nearly every sector of the global economy, sparing no industry." With 86,644 confirmed compromised devices, the FortiBleed campaign represents one of the largest known coordinated attacks on internet-facing security infrastructure.


    The threat landscape is particularly concerning because:


  • FortiGate appliances are critical chokepoints in network architecture—they control traffic between organizations and the internet
  • Compromised firewalls enable complete network reconnaissance before any lateral movement occurs
  • Attackers can monitor and intercept traffic, potentially capturing credentials for internal systems
  • The self-sustaining credential harvesting model means the attack will continue spreading unless organizations break the cycle through credential rotation

  • ---


    ## Implications: From Firewall to Full Compromise


    A compromised FortiGate appliance is not merely a "firewall breach"—it is a network visibility and control point for attackers. Once inside:


  • Threat actors can monitor all outbound and inbound connections
  • They can harvest credentials for internal services visible in network traffic
  • They can conduct sophisticated reconnaissance before engaging in theft or sabotage
  • They may maintain persistent access for months or years undetected

  • For organizations in sensitive sectors—telecom, government, and education—a compromised firewall could enable espionage, infrastructure manipulation, or data exfiltration at scale.


    ---


    ## Recommendations: Immediate and Long-Term Actions


    ### CISA's Immediate Guidance


    CISA has outlined the following critical steps for FortiGate customers:


    Immediate Actions (within 24-48 hours):

  • Terminate all active SSL VPN and administrative sessions
  • Reset all Fortinet administrator, system, and service accounts to new, unique, complex passwords
  • Enable multi-factor authentication (MFA) on all administrative access
  • Review FortiGate logs for evidence of unauthorized access or configuration changes
  • Implement network segmentation to restrict access to FortiGate administrative interfaces

  • Short-Term Hardening (within 1-2 weeks):

  • Change default credentials on all FortiGate appliances if not already completed
  • Upgrade FortiOS to the latest patched version supporting PBKDF2-based hashing
  • Implement strict access controls limiting who can access FortiGate interfaces
  • Deploy intrusion detection systems to monitor for suspicious traffic patterns
  • Audit all VPN user accounts and remove inactive or unnecessary credentials

  • Long-Term Resilience (ongoing):

  • Establish a credential rotation schedule (quarterly minimum for administrative accounts)
  • Implement centralized identity and access management (IAM) for network appliance access
  • Deploy security monitoring and user behavior analytics to detect compromised accounts
  • Conduct regular penetration testing of network perimeter devices
  • Maintain detailed asset inventories with firmware versioning information

  • ---


    ## HackWire Analysis: Default Credentials in 2026 Are Still a Mass Casualty Event


    Here's what stands out about FortiBleed: we are in 2026, and 86,644 organizations worldwide have failed to change default credentials on their firewalls. This isn't a zero-day exploit or an advanced persistent threat requiring nation-state resources. This is brute-force credential stuffing succeeding at massive scale because organizations have not implemented basic security hygiene.


    The credential breakdown is the real story. Organization-specific accounts representing 36.7% of compromises tells us that prior breaches are directly enabling current ones. When Fortinet leaks occur, or when credentials are exposed in other breaches, organizations are not rotating them. They're not treating compromised credentials as signals to harden their infrastructure. Instead, they're leaving those credentials sitting dormant until threat actors harvest them and use them again.


    The self-sustaining nature of this attack—where each compromise yields credentials to compromise more targets—is particularly damning for the software supply chain. When your firewall is compromised, every customer leveraging similar security postures becomes a target. Fortinet's advice to "follow best practices" is technically correct but functionally useless. Organizations clearly cannot implement basic practices on their own. This points to a systemic failure: either the tooling for credential management is inadequate, or organizations lack the operational discipline to use it.


    For defenders, the pattern is clear: treat any Fortinet installation as potentially compromised until proven otherwise. Review logs from the first day of 2026 forward. Assume that if your appliances were exposed and running default or weakly rotated credentials, they've been inside your network for months. The threat actors have a verified database of your credentials. Assume lateral movement. Assume persistence. Act accordingly.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Infrastructure Security](https://www.hackwire.news/category/infrastructure-security)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)