# FortiBleed: Russian IAB Harvests 110 Million Credentials from 430,000+ FortiGate Firewalls in Months-Long Campaign
A sophisticated credential-harvesting operation targeting Fortinet FortiGate firewalls has successfully compromised over 430,000 devices globally, harvesting approximately 110 million credentials in what researchers are calling FortiBleed. The campaign, attributed to a Russian-speaking initial access broker (IAB) and active since February 2026, represents one of the largest infrastructure-level compromise campaigns in recent years, with implications rippling across enterprises, government agencies, and critical infrastructure operators worldwide.
## The Threat
FortiBleed operates as a large-scale, systematic attack chain designed to enumerate, compromise, and harvest credentials from Fortinet FortiGate firewalls—a category of appliances that sit at network perimeters and are trusted to enforce security policies, manage VPNs, and control critical traffic flows.
Key statistics:
| Metric | Value |
|--------|-------|
| Firewalls Targeted | 430,000+ |
| Credentials Harvested | ~110 million |
| Campaign Start | February 2026 |
| Primary Target | FortiGate firewalls (all versions) |
| Affected Regions | Global |
| Primary Motivation | Financial gain / credential trafficking |
The operation follows a well-established playbook: reconnaissance, credential harvesting, brute-force attacks, and deployment of custom tooling to maintain persistence. The threat actor, assessed to be motivated primarily by financial return, appears to be an initial access broker—a specialist in acquiring network entry points for resale to other criminal groups or nation-state actors.
## Background and Context
### Why FortiGate Firewalls?
FortiGate appliances are deployed by an estimated 500,000+ organizations globally, including:
These devices serve as trust boundaries—if compromised, attackers gain visibility into and control over sensitive network traffic, VPN credentials, and internal communications. For an attacker or IAB, compromise of a FortiGate is equivalent to obtaining a skeleton key to an organization's network.
### The FortiBleed Campaign Timeline
February 2026: Campaign begins with systematic scanning of internet-facing FortiGate appliances to identify exposed management interfaces or accessible services.
March–June 2026: Threat actor deploys custom credential-harvesting tools, conducts brute-force attacks, and collects administrative credentials from compromised devices. Parallel to credential theft, exposed services are enumerated to identify secondary attack vectors.
June 2026: Security researchers identify the coordinated campaign and link over 430,000 devices to the operation based on telemetry, scanning patterns, and credential leakage indicators.
## Technical Details
### Attack Methodology
FortiBleed follows a multi-stage attack pattern:
1. Reconnaissance & Enumeration
- Threat actor scans for internet-exposed FortiGate management interfaces (typically TCP 443, 8443, 10443)
- Identifies FortiGate devices using banner-grabbing and version detection
- Cross-references with SHODAN, Censys, and other internet scanning databases
2. Credential Harvesting
- Deploys custom tools to extract stored credentials from compromised FortiGate configurations
- Harvests plaintext or reversible-encrypted credentials stored in device memory or persistent storage
- Collects VPN credentials, administrative accounts, and API tokens
- Harvesting tools designed to be stealthy, avoiding detection by native FortiGate logging
3. Brute-Force Attacks
- Uses harvested or common credential lists to brute-force remaining FortiGate appliances
- Targets weak or default credentials on management interfaces
- Success rate estimated at 15–20% based on leaked credential databases
4. Persistence & Exploitation
- Deploys bespoke webshells or backdoors within FortiGate web interface
- Modifies authentication mechanisms to maintain access
- Exfiltrates additional credentials and configuration data
### Credential Quality & Market Value
The 110 million harvested credentials represent a high-value intelligence haul:
These credentials are being sold or distributed on Russian-language forums, enabling secondary attacks by ransomware gangs, nation-state actors, and other cybercriminals.
## Implications
### Organizational Risk
Organizations with FortiGate firewalls are exposed to multiple downstream risks:
### Sector-Specific Impact
Financial Services:
Healthcare:
Government & Defense:
Critical Infrastructure:
## Recommendations
### Immediate Actions
Organizations should execute the following measures within 48–72 hours:
1. Access Control Review
- Identify all internet-exposed FortiGate management interfaces
- Restrict access to management interfaces to trusted IP ranges or VPNs
- Disable or change default administrative credentials
- Enforce strong password policies (minimum 14+ character complex passwords)
2. Credential Audit
- Change all FortiGate administrative passwords
- Rotate VPN and service account credentials
- Reset API keys and authentication tokens
- Monitor for unauthorized credential use in downstream systems
3. Threat Hunting
- Search FortiGate logs for suspicious authentication events (failed logins, off-hours access, unusual source IPs)
- Check for unauthorized administrative accounts or API users created after February 2026
- Review firewall policy changes for unauthorized modifications
### Medium-Term Actions
4. Segmentation & Network Hardening
- Assume FortiGate credentials may be compromised; implement network micro-segmentation
- Restrict VPN access to specific systems or subnets rather than full network access
- Implement multi-factor authentication (MFA) for VPN access and administrative logins
- Deploy intrusion detection/prevention systems (IDS/IPS) to monitor for lateral movement
5. Monitoring & Response
- Enable enhanced logging on all FortiGate appliances
- Deploy Security Information and Event Management (SIEM) to correlate FortiGate logs with network activity
- Create alert rules for suspicious authentication patterns, policy changes, and credential exfiltration
- Establish incident response procedures for potential FortiGate compromise
6. Vendor Coordination
- Engage Fortinet support to assess whether your devices show signs of compromise
- Request security patches or firmware updates if available
- Subscribe to Fortinet security advisories for emerging FortiBleed-related threats
---
## HackWire Analysis
FortiBleed exposes a critical blind spot in enterprise security: perimeter appliances like FortiGates are often treated as "set and forget" infrastructure, receiving fewer security updates, weaker password policies, and less monitoring than internal systems. Yet they represent the most valuable compromise for attackers—a single compromised firewall often provides better access than a thousand compromised workstations.
The timing and scale of FortiBleed also signal a troubling trend in threat actor specialization. Rather than pursuing broad-based network intrusions, sophisticated IABs are now targeting specific high-value appliances and selling access to downstream criminals. This modular approach to cybercrime means organizations can't simply patch their way out: they must assume that if their FortiGate credentials were weak or default, they've likely been compromised, regardless of whether they've seen active exploitation yet.
For defenders, this campaign underscores three hard truths: (1) perimeter appliances require the same access controls and monitoring as critical internal systems; (2) credentials stored or processed by network devices will eventually be harvested if attackers gain code execution; and (3) the time between compromise and detection is often measured in months, not hours. Organizations should prioritize credential rotation, network segmentation, and continuous monitoring of their infrastructure-layer security posture.
— *HackWire Editorial*
---
## Related Coverage