International cybersecurity agencies, including the United States Cybersecurity and Infrastructure Security Agency (CISA), the United Kingdom’s National Cyber Security Centre (NCSC), and the Australian Cyber Security Centre (ACSC), have issued coordinated emergency advisories following a massive global cyber campaign dubbed “FortiBleed”. The sweeping operation has exposed over 86,600 verified administrative and SSL VPN login credentials belonging to enterprise networks, telecom operators, and government entities across 194 countries.
The critical vulnerability exposure was uncovered after threat intelligence researchers discovered an unsecured operational server maintained by a threat actor group, hosting active credentials for internet-facing Fortinet FortiGate firewalls and security gateways. Operating continuously since at least early 2026, the campaign underscores a significant strategic shift among cybercriminals toward exploiting valid user identities and default credentials rather than relying exclusively on complex zero-day software vulnerabilities to breach corporate network perimeters.
Automated Credential Harvesting and the FortiBleed Mechanism
The technical mechanics driving the FortiBleed campaign rely on a highly automated, self-sustaining attack framework engineered to compromise perimeter appliances at a global scale. Rather than deploying novel software exploits, the threat actors utilize specialized scanning engines to systematically map the public internet for exposed FortiGate login portals and administrative interfaces. Once an active endpoint is identified, the automated framework executes high-speed credential stuffing and password spraying attacks using curated databases composed of factory default account names, weak administrative passwords, and credentials leaked from historical breaches.
Once initial access to a target FortiGate appliance is established, the compromise quickly transitions into an active surveillance and credential harvesting phase. The compromised firewall or SSL VPN gateway is effectively converted into a covert listening post that passively monitors live enterprise network traffic passing through the appliance. By inspecting unencrypted communications and session data, the attackers harvest additional employee credentials, internal administrative tokens, and sensitive network configuration files, which are automatically exfiltrated back to the central operational server to fuel further automated intrusions across linked corporate networks.
Geopolitical Scope and Sectoral Impact Across 194 Countries
In-depth technical analysis of the leaked database conducted by cybersecurity firms including SOCRadar and Hudson Rock revealed that default administrative accounts and factory system profiles accounted for over 63 percent of the exposed credentials. This disproportionate reliance on default settings highlights a critical systemic failure among enterprise administrators to rename default accounts or rotate initial setup passwords. The remaining 37 percent comprised organization-specific accounts, indicating that threat actors successfully harvested credentials created by organizations themselves or sourced from secondary breach repositories.
The geographic and sectoral footprint of the FortiBleed campaign spans 194 countries, with the highest concentration of compromised appliances identified across India, the United States, Mexico, Colombia, and Thailand. Cybersecurity researchers have linked aspects of the campaign to Russian-speaking threat actors actively gathering intelligence on entities connected to NATO allies and defense manufacturing supply chains. By leveraging valid, authenticated access to boundary firewalls, attackers can bypass traditional security controls, deploy stealthy tunneling utilities like Chisel and Neo-reGeorg, and establish persistent footholds to stage lateral movement or deploy destructive ransomware payloads.
Urgent Remediation and Technical Hardening Mandates
In light of the severe operational risks posed by the FortiBleed campaign, CISA and international cybersecurity partners strongly urge all organizations utilizing FortiGate firewalls and SSL VPN gateways to assume immediate exposure and execute emergency remediation protocols. Network administrators must instantly terminate all active administrative and SSL VPN sessions across their environments, force a mandatory, organization-wide password reset for all local and remote access accounts, and enforce robust, phishing-resistant Multi-Factor Authentication (MFA) across every remote access gateway.
Beyond immediate credential rotation, cybersecurity authorities emphasize the necessity of structural perimeter hardening and software updates. Organizations must immediately block external internet access to FortiGate administrative management interfaces, restricting management capabilities strictly to trusted internal IP ranges or isolated out-of-band networks. Furthermore, administrators are urged to update device firmware to supported FortiOS versions, such as branches 7.4, 7.6, or 8.0, which incorporate PBKDF2 password hashing to prevent exfiltrated configuration files and credential hashes from being cracked offline using high-performance GPU arrays.
