# FortiBleed: Russian IAB Harvests 110 Million Credentials from 430,000+ FortiGate Firewalls in Months-Long Campaign


A sophisticated credential-harvesting operation targeting Fortinet FortiGate firewalls has successfully compromised over 430,000 devices globally, harvesting approximately 110 million credentials in what researchers are calling FortiBleed. The campaign, attributed to a Russian-speaking initial access broker (IAB) and active since February 2026, represents one of the largest infrastructure-level compromise campaigns in recent years, with implications rippling across enterprises, government agencies, and critical infrastructure operators worldwide.


## The Threat


FortiBleed operates as a large-scale, systematic attack chain designed to enumerate, compromise, and harvest credentials from Fortinet FortiGate firewalls—a category of appliances that sit at network perimeters and are trusted to enforce security policies, manage VPNs, and control critical traffic flows.


Key statistics:


| Metric | Value |

|--------|-------|

| Firewalls Targeted | 430,000+ |

| Credentials Harvested | ~110 million |

| Campaign Start | February 2026 |

| Primary Target | FortiGate firewalls (all versions) |

| Affected Regions | Global |

| Primary Motivation | Financial gain / credential trafficking |


The operation follows a well-established playbook: reconnaissance, credential harvesting, brute-force attacks, and deployment of custom tooling to maintain persistence. The threat actor, assessed to be motivated primarily by financial return, appears to be an initial access broker—a specialist in acquiring network entry points for resale to other criminal groups or nation-state actors.


## Background and Context


### Why FortiGate Firewalls?


FortiGate appliances are deployed by an estimated 500,000+ organizations globally, including:

  • Enterprise networks
  • Financial institutions
  • Government agencies
  • Healthcare systems
  • Critical infrastructure operators

  • These devices serve as trust boundaries—if compromised, attackers gain visibility into and control over sensitive network traffic, VPN credentials, and internal communications. For an attacker or IAB, compromise of a FortiGate is equivalent to obtaining a skeleton key to an organization's network.


    ### The FortiBleed Campaign Timeline


    February 2026: Campaign begins with systematic scanning of internet-facing FortiGate appliances to identify exposed management interfaces or accessible services.


    March–June 2026: Threat actor deploys custom credential-harvesting tools, conducts brute-force attacks, and collects administrative credentials from compromised devices. Parallel to credential theft, exposed services are enumerated to identify secondary attack vectors.


    June 2026: Security researchers identify the coordinated campaign and link over 430,000 devices to the operation based on telemetry, scanning patterns, and credential leakage indicators.


    ## Technical Details


    ### Attack Methodology


    FortiBleed follows a multi-stage attack pattern:


    1. Reconnaissance & Enumeration

    - Threat actor scans for internet-exposed FortiGate management interfaces (typically TCP 443, 8443, 10443)

    - Identifies FortiGate devices using banner-grabbing and version detection

    - Cross-references with SHODAN, Censys, and other internet scanning databases


    2. Credential Harvesting

    - Deploys custom tools to extract stored credentials from compromised FortiGate configurations

    - Harvests plaintext or reversible-encrypted credentials stored in device memory or persistent storage

    - Collects VPN credentials, administrative accounts, and API tokens

    - Harvesting tools designed to be stealthy, avoiding detection by native FortiGate logging


    3. Brute-Force Attacks

    - Uses harvested or common credential lists to brute-force remaining FortiGate appliances

    - Targets weak or default credentials on management interfaces

    - Success rate estimated at 15–20% based on leaked credential databases


    4. Persistence & Exploitation

    - Deploys bespoke webshells or backdoors within FortiGate web interface

    - Modifies authentication mechanisms to maintain access

    - Exfiltrates additional credentials and configuration data


    ### Credential Quality & Market Value


    The 110 million harvested credentials represent a high-value intelligence haul:

  • Administrative credentials for FortiGate devices (selling for $500–$2,000+ per valid credential on underground markets)
  • VPN credentials enabling remote network access (valued at $100–$500 per credential)
  • API keys and service accounts for downstream lateral movement
  • Credentials for connected systems (firewalls often protect or integrate with other critical infrastructure)

  • These credentials are being sold or distributed on Russian-language forums, enabling secondary attacks by ransomware gangs, nation-state actors, and other cybercriminals.


    ## Implications


    ### Organizational Risk


    Organizations with FortiGate firewalls are exposed to multiple downstream risks:


  • Network Reconnaissance: Attackers with valid credentials gain visibility into VLANs, routing tables, VPN configurations, and internal network topology
  • Lateral Movement: Compromised FortiGate appliances serve as pivot points for lateral movement into internal networks
  • Data Exfiltration: Attackers can configure policy exceptions, redirect traffic, or deploy monitoring tools to capture sensitive data in transit
  • Ransomware Deployment: Initial access brokers frequently sell FortiGate credentials to ransomware operations, resulting in full-network encryption and extortion
  • Supply Chain Risk: Compromise of upstream network devices (like firewalls) creates risk for all downstream systems and users

  • ### Sector-Specific Impact


    Financial Services:

  • Access to payment processing networks, wire transfer systems, and account management infrastructure
  • Potential for unauthorized funds transfer or account takeover

  • Healthcare:

  • Compromise of medical device networks, patient data systems, and VPN infrastructure
  • Risk to patient safety if medical devices are compromised or isolated

  • Government & Defense:

  • Compromise of classified networks or sensitive government systems
  • Potential counterintelligence risk

  • Critical Infrastructure:

  • Compromise of SCADA networks, industrial control systems, and operational technology
  • Risk to power grids, water systems, and communications infrastructure

  • ## Recommendations


    ### Immediate Actions


    Organizations should execute the following measures within 48–72 hours:


    1. Access Control Review

    - Identify all internet-exposed FortiGate management interfaces

    - Restrict access to management interfaces to trusted IP ranges or VPNs

    - Disable or change default administrative credentials

    - Enforce strong password policies (minimum 14+ character complex passwords)


    2. Credential Audit

    - Change all FortiGate administrative passwords

    - Rotate VPN and service account credentials

    - Reset API keys and authentication tokens

    - Monitor for unauthorized credential use in downstream systems


    3. Threat Hunting

    - Search FortiGate logs for suspicious authentication events (failed logins, off-hours access, unusual source IPs)

    - Check for unauthorized administrative accounts or API users created after February 2026

    - Review firewall policy changes for unauthorized modifications


    ### Medium-Term Actions


    4. Segmentation & Network Hardening

    - Assume FortiGate credentials may be compromised; implement network micro-segmentation

    - Restrict VPN access to specific systems or subnets rather than full network access

    - Implement multi-factor authentication (MFA) for VPN access and administrative logins

    - Deploy intrusion detection/prevention systems (IDS/IPS) to monitor for lateral movement


    5. Monitoring & Response

    - Enable enhanced logging on all FortiGate appliances

    - Deploy Security Information and Event Management (SIEM) to correlate FortiGate logs with network activity

    - Create alert rules for suspicious authentication patterns, policy changes, and credential exfiltration

    - Establish incident response procedures for potential FortiGate compromise


    6. Vendor Coordination

    - Engage Fortinet support to assess whether your devices show signs of compromise

    - Request security patches or firmware updates if available

    - Subscribe to Fortinet security advisories for emerging FortiBleed-related threats


    ---


    ## HackWire Analysis


    FortiBleed exposes a critical blind spot in enterprise security: perimeter appliances like FortiGates are often treated as "set and forget" infrastructure, receiving fewer security updates, weaker password policies, and less monitoring than internal systems. Yet they represent the most valuable compromise for attackers—a single compromised firewall often provides better access than a thousand compromised workstations.


    The timing and scale of FortiBleed also signal a troubling trend in threat actor specialization. Rather than pursuing broad-based network intrusions, sophisticated IABs are now targeting specific high-value appliances and selling access to downstream criminals. This modular approach to cybercrime means organizations can't simply patch their way out: they must assume that if their FortiGate credentials were weak or default, they've likely been compromised, regardless of whether they've seen active exploitation yet.


    For defenders, this campaign underscores three hard truths: (1) perimeter appliances require the same access controls and monitoring as critical internal systems; (2) credentials stored or processed by network devices will eventually be harvested if attackers gain code execution; and (3) the time between compromise and detection is often measured in months, not hours. Organizations should prioritize credential rotation, network segmentation, and continuous monitoring of their infrastructure-layer security posture.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)