A large-scale campaign dubbed FortiBleed harvested credentials from internet-facing Fortinet devices, with researchers reporting stolen data from more than 70,000 to 75,000 devices across up to 194 countries and evidence that more than 430,000 FortiGate firewalls were targeted. SOCRadar said the operators used default or previously leaked credentials to access devices, deployed a custom packet-sniffing implant known as FortiGate Sniffer, captured VPN and other authentication data in real time, and in some cases left persistent backdoor accounts such as adminin. Open-source reporting and government alerts also tied the activity to Fortinet flaws including CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719, while Fortinet disputed claims that the exposed credentials reflected a new product breach and said some data may have come from earlier compromises or brute-force activity.
The stolen access was allegedly linked to the INC and Lynx ransomware ecosystems, with researchers citing exposed infrastructure, ransomware negotiation-panel artifacts, credential-stuffing systems, and cases where intrusions progressed to encryption of hundreds of endpoints. Reports said credentials belonging to UK government officials, Foreign Office staff, embassy personnel, NHS trusts, local councils, energy firms, and pharmaceutical suppliers were offered for sale on dark-web forums, raising concern over follow-on attacks against sensitive networks. National defenders including the UK NCSC and Brazil's CTIR Gov urged organizations using Fortinet firewalls and SSL VPNs to review accounts, remove unauthorized users, terminate sessions, reset passwords, enforce MFA, patch affected systems, and inspect logs for signs of compromise and lateral movement.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer published SOCRadar STRU's report on July 1, 2026, describing FortiBleed as a large-scale credential theft campaign targeting Fortinet FortiGate devices. The research said an exposed server held stolen credentials from more than 73,000 devices, configuration files, and infrastructure for hash cracking and credential stuffing.
In late June 2026, Bob Diachenko discovered an internet-exposed server containing a database of tens of thousands of FortiGate and Fortinet VPN device URLs, usernames, email addresses, and plaintext passwords. Researchers also described the server as holding internal files, logs, automation scripts, and operational data tied to the campaign.
Researchers assessed that the FortiBleed credential-theft campaign had been active since at least February 2026, using mass internet scanning plus default and previously leaked credentials to access Fortinet devices. Attackers then installed a Go-based sniffer on compromised systems to intercept traffic and harvest credentials.
The UK National Cyber Security Centre confirmed that a brute-force campaign against Fortinet devices was underway and urged organizations to inspect networks, isolate compromised devices, and change passwords immediately. The report said UK authorities had not established direct evidence tying the activity to the Russian state.
Cybersecurity reporting said credentials belonging to UK government officials and Foreign Office staff were exposed and offered for sale on dark web forums as part of FortiBleed. Reported victims also included NHS trusts, energy companies, local councils, and embassy staff, with some Foreign Office access advertised for tens of thousands of pounds.
Researchers linked FortiBleed infrastructure to the INC and Lynx ransomware operations after finding artifacts on a Windows server, including browser sessions showing access to ransomware negotiation panels and chats with victims. They also reported overlap between FortiBleed victims and organizations listed on the INC leak site.
CTIR Gov updated Alert 50/2026 on June 19, 2026, continuing to warn of active exploitation and roughly 75,000 devices with potentially compromised credentials reported in open sources. The update maintained guidance on patching, removing unauthorized accounts, and reviewing indicators of compromise.
On June 15, 2026, Brazil's CTIR Gov published Alert 50/2026 warning of a large-scale FortiBleed campaign affecting internet-exposed Fortinet devices and linking it to CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719. The alert recommended immediate mitigation steps including account review, password resets, MFA, firmware updates, and log analysis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourcescworld.com
Open sourceitpro.com
Open sourceeuronews.al
Open sourcexakep.ru
Open sourcecyberveille.ch
Open sourcegov.br
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.