READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

FortiBleed: Russian-Linked Hackers Compromised Fortinet Firewalls at 73,000 Sites Across 194 Countries

FortiBleed: Russian-Linked Hackers Compromised Fortinet Firewalls at 73,000 Sites Across 194 Countries
A campaign dubbed FortiBleed has exposed verified VPN credentials for tens of thousands of Fortinet firewalls at major corporations and government agencies worldwide. The attackers are not exploiting a new software flaw. They are logging in with passwords that companies never bothered to change or that were already stolen in earlier breaches.

What happened

Security researcher Volodymyr "Bob" Diachenko found an exposed server containing what appeared to be working Fortinet VPN credentials, usernames, email addresses, and plaintext passwords, for 73,932 unique firewall URLs spanning 194 countries and 21,632 domains, according to Hudson Rock, the threat intelligence firm that published a formal analysis after Diachenko shared the dataset.

SOCRadar, a second cybersecurity firm, put the compromised device count at more than 30,000 in a separate report published the same day. The gap between the two figures likely reflects different methodologies for counting verified versus candidate entries.

The named targets are not small businesses. According to Hudson Rock and BleepingComputer's reporting on Diachenko's findings, the exposed data includes entries for Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, PwC, AT&T, Chevron, Mercedes-Benz, Toyota, Spotify, and Sony. Government agencies, telecom carriers, and critical infrastructure operators also appear in the dataset, per SOCRadar. A Lenovo spokesperson acknowledged TechCrunch's request for comment and did not respond. None of the other named companies responded to requests for comment.

How the attackers did it

Fortinet spokesperson Tiffany Curci told TechCrunch that the company's analysis indicates "the data involved is a resharing of data from previous incidents, as well as bruteforcing of credentials, and is not related to any recent incident or advisory."

Fortinet's framing deserves scrutiny as an interested party, but the technical details from independent researchers are consistent with it. According to Diachenko's investigation, as reported by BleepingComputer and Hackread, the group ran approximately 1.16 billion credential attempts against more than 320,000 FortiGate targets and an additional 2.1 billion attempts against more than 163,000 Microsoft SQL Server systems. The attackers allegedly intercepted SSL VPN authentication hashes, cracked them using a 45-GPU cluster managed through a tool called Hashtopolis, then used the recovered credentials to move laterally into internal Active Directory environments.

Once inside a device, the operation becomes self-sustaining. SOCRadar described it plainly: the compromised firewall acts as a listening post, capturing credentials flowing through VPN traffic, which are then fed back into the scanner to hit more targets.

Hackread's reporting on Hudson Rock's analysis adds an important technical nuance. Many successful logins used complex passwords, not simple ones. The attackers were not guessing. They were testing passwords already stolen through prior breaches or infostealer malware. Complexity requirements are irrelevant when the attacker already has your password.

The Russian-speaking connection

Both Hudson Rock and SOCRadar say the group behind FortiBleed appears to be Russian-speaking. Diachenko described it as a multi-operator threat group. No nation-state attribution has been made publicly, and no government agency has formally identified the actors as of June 17, 2026.

Diachenko also reported deeper compromises in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor from which classified documents were allegedly stolen. Hackread noted that claim has not been independently confirmed by Fortinet in any public material. It should be treated as an allegation from Diachenko's investigation, not an established fact.

The countries with the most affected devices, according to both Hudson Rock and SOCRadar, are India, the United States, Taiwan, and Mexico. Most-affected industries include IT services, construction materials, and telecommunications.

The strongest counterargument

Fortinet's position, and the position a reasonable defender of the company would advance, is that this is credential hygiene failure at the customer level, not a product failure. If organizations had rotated passwords, enforced multi-factor authentication, and audited which credentials were already compromised in prior breaches, the vast majority of these intrusions would not have happened. Fortinet devices themselves were not exploited through a software vulnerability. The attackers logged in through the front door with keys the tenants left lying around.

That argument is technically accurate but incomplete. Enterprise customers deploy Fortinet precisely because they are buying a security product. When tens of thousands of those customers share the same failure mode at the same time, the product vendor has a responsibility to push harder on credential enforcement, flag reused or known-compromised passwords at the device level, and make MFA the default, not an option.

What organizations should do now

Hudson Rock launched a free lookup portal where organizations can check whether their domains appear in the FortiBleed dataset. Arctic Wolf also published a technical advisory on June 17 covering the campaign and recommended immediate credential audits for any internet-exposed Fortinet devices.

A key unresolved question is how many of the 73,932 listed firewall URLs represent active, ongoing access versus credentials that have since been rotated or revoked. Fortinet has not provided a number. Hudson Rock has not provided one either. Until someone does, affected organizations have no way to know whether they are looking at a historical snapshot or a live set of working keys.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Ars TechnicaMassive breach spills credentials for thousands of sensitive networks
center-left
TechCrunchCybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world
unknown
bleepingcomputerFortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. - Bleeping Computer
unknown
hackreadFortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries - Hackread
unknown
arcticwolfActive FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries - Arctic Wolf