# FortiBleed: Massive Fortinet VPN Credential Leak Exposes 73,000+ Devices Worldwide


A sprawling data breach dubbed FortiBleed has exposed VPN credentials for over 73,000 Fortinet FortiGate firewall devices, affecting major corporations and government agencies across nearly 200 countries. The leak represents one of the largest known collections of compromised enterprise VPN credentials and provides a detailed roadmap of successful intrusions by a sophisticated Russian-speaking threat group.


Security researcher Bob Diachenko discovered the exposed data on an unsecured server containing plaintext VPN usernames, emails, and passwords for some of the world's largest organizations—including Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, and others. The incident reveals not only the credentials themselves but also the infrastructure, tools, and operational details of a sprawling cyberespionage campaign that conducted over 3 billion credential attempts against enterprise security appliances.


## The Threat: Scope and Scale


The FortiBleed leak exposes a coordinated, sustained attack against Fortinet infrastructure at an unprecedented scale:


| Metric | Number |

|--------|---------|

| Unique Firewall URLs Exposed | 73,932 |

| Unique Affected Domains | 21,632 |

| Countries Impacted | 194 |

| Credential Attempts (FortiGate) | 1.16 billion |

| FortiGate Targets Probed | 320,777 |

| Credential Attempts (SQL Server) | 2.1 billion |

| SQL Server Targets Probed | 163,650 |


According to threat intelligence firm Hudson Rock, which published a detailed analysis after receiving the dataset from Diachenko, this represents one of the largest known troves of compromised Fortinet credentials ever documented. The exposed data includes organizational intelligence such as industry classification, revenue figures, and employee counts—metadata clearly intended to inform targeting decisions and attack prioritization.


### Geographic Distribution


The highest concentration of affected devices appears in:


  • India (largest affected region)
  • United States
  • Taiwan
  • Mexico
  • Turkey
  • Thailand
  • Colombia
  • Malaysia
  • Chile
  • United Arab Emirates

  • The global distribution underscores how the threat actors systematically targeted enterprise infrastructure across multiple continents and time zones.


    ## Background and Context: How the Breach Occurred


    Diachenko's investigation revealed that the threat group behind FortiBleed operated with industrial precision. After gaining credentials through various means—including credential stuffing, brute force attacks, and likely exploitation of previous breaches—the attackers took systematic steps to maximize the value of their access.


    The Attack Workflow:


    1. Credential Harvesting — Attackers conducted over 3 billion credential attempts against FortiGate SSL VPN devices and Microsoft SQL Server systems, using standard credential-guessing techniques.


    2. Hash Interception — The group intercepted SSL VPN authentication hashes from captured traffic or compromised systems.


    3. Distributed Cracking — Using a 45-GPU cluster managed through Hashtopolis (an open-source hashcracking management system), the attackers cracked captured password hashes at scale.


    4. Lateral Movement — With recovered credentials in hand, attackers moved laterally into internal Active Directory environments and deeper network infrastructure.


    5. Persistence and Exfiltration — The group maintained detailed logs of successful compromises and assembled a comprehensive database of verified credentials for strategic targeting.


    What makes this campaign particularly notable is that the attackers inadvertently left an open directory on the same server containing their operational artifacts—connection strings, custom scripts, tooling, cron job logs, and bash histories. This operational security failure gave researchers unprecedented visibility into a live, active campaign.


    ## Technical Details: The Exposed Infrastructure


    The exposed database contains 73,932 unique firewall URLs representing FortiGate SSL VPN access points for organizations worldwide. The credentials themselves are unusual: many include long, complex passwords that would ordinarily be considered resistant to traditional cracking attacks, suggesting either:


  • Extraction from FortiGate configuration files (rather than brute force alone)
  • Recovery from previous breaches of the target organizations
  • Successful hash cracking using the attackers' substantial computational resources

  • The metadata attached to each credential entry paints a comprehensive targeting picture. Each organization entry includes:


  • Industry classification (to identify high-value sectors)
  • Revenue figures (to assess organizational size and resources)
  • Employee counts (to estimate internal network complexity)
  • Successful compromise indicators (documenting which credentials actually worked)

  • ## Confirmed Compromises and Casualties


    Hudson Rock and Diachenko's investigation identified multiple fully compromised organizations:


    Confirmed Impact:

  • Organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey with full network compromise
  • A Turkish NATO defense contractor from which classified documents were allegedly stolen
  • Multiple government agencies and critical infrastructure operators

  • Organizations in the Dataset (Partial List):

  • Technology: Foxconn, Samsung, Lenovo, Siemens, Oracle
  • Professional Services: PwC, Accenture
  • Telecommunications: Comcast, AT&T
  • Energy: Chevron, Sinopec, State Grid
  • Automotive: Mercedes-Benz, Toyota
  • Government & Defense: Numerous agencies and military contractors

  • The presence of critical infrastructure operators and defense contractors in the dataset elevates the severity beyond typical corporate espionage.


    ## Implications: What Organizations Face


    FortiBleed presents multiple layers of risk:


    ### Immediate Threats

  • Direct VPN Access — Attackers possess working credentials to enterprise VPN infrastructure, enabling remote code execution and lateral movement.
  • Active Exploitation — The campaign appears ongoing, with operational logs indicating active targeting and compromise attempts.
  • Advanced Targeting — The attackers' detailed organizational intelligence suggests they are strategically prioritizing targets for deeper exploitation.

  • ### Broader Risks

  • Supply Chain Exposure — The compromised organizations span technology suppliers, manufacturers, and infrastructure providers, creating cascading risk for downstream customers.
  • Espionage and IP Theft — The involvement of defense contractors and the theft of classified documents indicates state-sponsored or state-adjacent targeting.
  • Credential Reuse — Employees whose credentials appear in the dataset likely reuse passwords across multiple systems, extending the blast radius.

  • ### Affected Industries

    The dataset disproportionately affects:

  • Telecommunications — primary target sector
  • IT Services & Software
  • Financial Services
  • Government & Defense
  • Healthcare Providers
  • Manufacturing
  • Education

  • Healthcare providers should review their security posture—for health information resources, visit [VitaGuia](https://www.vitaguia.com) or [Lake Nona Medical Services](https://www.nonamedicalservices.com).


    ## Recommendations: Immediate Actions


    Organizations should take the following steps immediately:


    ### Priority 1: Credential Rotation (Within 24 Hours)

  • Identify all Fortinet VPN administrator accounts and force password changes
  • Rotate SSL VPN service accounts used for automated access
  • Audit Active Directory for accounts associated with VPN access
  • Reset SSH keys and API tokens if any were shared on VPN-connected systems

  • ### Priority 2: Access Review (Within 48 Hours)

  • Check VPN logs for suspicious access patterns dating back at least 90 days
  • Monitor for lateral movement into critical systems following VPN entry points
  • Review Active Directory logs for unusual authentication patterns or privilege escalation
  • Search for indicators of compromise (IOCs) provided by Hudson Rock and security researchers

  • ### Priority 3: Containment (Ongoing)

  • Implement network segmentation to limit VPN-to-internal-network access
  • Deploy multi-factor authentication (MFA) on all VPN access
  • Enable MFA on all Active Directory administrative accounts
  • Configure alerts for bulk credential usage or unusual access patterns

  • ### Priority 4: Long-Term Hardening

  • Assess Fortinet configuration security and disable unnecessary features
  • Review and update default credentials across all appliances
  • Implement certificate pinning for VPN access
  • Deploy endpoint detection and response (EDR) solutions on systems accessing VPN resources
  • Conduct forensic analysis if compromise is suspected

  • ## HackWire Analysis


    FortiBleed represents a critical inflection point for enterprise security. For years, security professionals have warned about the inadequacy of VPN-as-perimeter defense, and this leak proves those warnings prescient. What distinguishes FortiBleed from typical breaches is the operational transparency it provides: the attackers essentially left behind their complete playbook, showing not just what credentials they stole, but how they stole them, at what scale, and with what resources.


    The 45-GPU hashcracking cluster is particularly significant. This reveals that modern credential attacks no longer depend on guessing weak passwords—instead, sophisticated attackers are investing in computational infrastructure to crack strong hashes at scale. The shift from "spray and pray" credential stuffing to targeted, hash-driven credential recovery means that organizations relying on password complexity alone face a false sense of security.


    More troubling is the *geographic footprint*. The concentration of affected infrastructure in NATO-adjacent countries (Turkey, India hosting multinational IT services, Eastern European manufacturers) and the theft of classified documents from a Turkish defense contractor strongly suggest state-sponsored activity. This is not opportunistic cybercriminals selling access to the dark web—this is a sophisticated multi-operator group with operational infrastructure, cracking capabilities, and strategic targeting. The presence of their operational logs and tools in the exposed directory indicates they don't fear discovery, suggesting either confidence in their tradecraft or institutional backing.


    For defenders, the immediate lesson is this: VPN credentials are now a commodity to be assumed compromised. Organizations should shift from "protect your credentials" to "assume they're already in the wild" and architect accordingly. Multi-factor authentication stops being a "nice to have" and becomes a critical control. Network segmentation from VPN entry points becomes non-negotiable. And for organizations in the leaked dataset, forensic investigation isn't optional—it's mandatory.


    — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)