Threat Analysis·18 June 2026

FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Glowing padlocks and binary code leaking from a dark Fortinet-style firewall appliance in a server rack
Threat Analysis

Article record

Threat AnalysisCategory
18 June 2026Published
4 min readReading time
Mark FermorWritten by
Glowing padlocks and binary code leaking from a dark Fortinet-style firewall appliance in a server rack

Why it matters

What this means for organisations holding critical data

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

Researchers have uncovered a mass compromise of Fortinet firewalls that has handed a Russian-speaking criminal crew near-unrestricted access to some of the world''s largest organisations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defence contractor and Fortinet itself.

According to Bob Diachenko of SecurityDiscovery.com, nearly 74,000 Fortinet devices across more than 21,000 IP addresses in 194 countries have been compromised, with their plaintext credentials exposed online. Independent researcher Kevin Beaumont confirms that "almost all" of the affected devices remained online as of this week, and that the credentials are real and current. By Shodan''s count, that is roughly half of every internet-facing Fortinet firewall on the planet.

What happened

The attackers mass-scanned the public internet for FortiGate remote login endpoints, then sprayed them with thousands of username and password combinations using a custom 25,000-thread binary. Each success gave them, in Diachenko''s words, "a network tap inside the organisation".

From there, Hudson Rock reports, the crew intercepted SSL VPN authentication hashes and fed them to a 45-GPU Hashtopolis cluster running a 12-level recursive cracking pipeline. Successful guesses were looped back as seeds for the next round, so the attack got faster and smarter the more it succeeded. Once cracked, those passwords were used to move laterally into Active Directory, Radius and other centralised authentication systems.

"The scale is the sophistication," Diachenko told Ars Technica.

Who is affected

The exposed database also lists the industry, revenue and employee count for each compromised organisation. Named victims include Oracle, Chevron, Lenovo, Federal Express, Foxconn, Samsung, Comcast, Siemens, PwC, Accenture and Fortinet itself, alongside what Hudson Rock describes as "thousands of others, including major government agencies and critical infrastructure providers".

The most serious confirmed case is a Turkish NATO defence contractor, from which the group is said to have successfully exfiltrated classified defence documents. Diachenko''s investigation confirmed full network compromises at organisations across Japan, Taiwan, Vietnam, Iraq and Turkey. The top affected sectors are IT services, construction materials, telecommunications, construction and engineering, industrial equipment and financial services.

Why this matters

Firewalls have always been an attractive entry point. They sit on the perimeter, accept connections from the open internet, and broker access to the most valuable resources inside the network. When a single product line is this widely deployed, a working credential database becomes a master key to half the economy.

What is striking about FortiBleed is not a novel zero-day but the brute, industrial scale of the operation. Tens of thousands of passwords cracked at scale, fed back into a self-improving pipeline, then quietly used to pivot into Active Directory. The perimeter held the door; the attackers simply made enough keys.

The Firevault view

This is the failure mode Firevault was built to remove. If your recovery keys, root credentials, succession material or long-term audit secrets sit on a system that an internet-facing firewall can reach, then a cracked VPN hash, somewhere in the world, can reach them too.

An offline secure storage module is not a replacement for a firewall. It is a physically separate place to hold the material that must survive a perimeter compromise, including the credentials you would need to recover from one. A Firebreak deployment keeps that material in a tamper-evident enclosure, with no network path that a Hashtopolis cluster can ever reach. The question we keep putting to security leaders is simple: if your perimeter was in the FortiBleed dataset tomorrow, what would you wish had never been online?

What to do now

  • Check your domains against Hudson Rock''s lookup at hudsonrock.com/fortinet.
  • Force rotate Fortinet admin, SSL VPN, Radius and Active Directory credentials, then audit for lateral movement that pre-dates the rotation.
  • Review logs on FortiGate appliances for high-volume authentication attempts and anomalous successful logins from unfamiliar geographies.
  • Move long-life secrets, recovery keys and succession material into an offline, physically air-gapped store. Talk to us about gold-copy backups and Firebreak deployments.

Sources

Analysis by Mark Fermor, Firevault.

How Firevault helps

  • Offline Secure Storage keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
  • Control gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.
  • Firebreak delivers hardware-enforced disconnection at Layer 1, so exposed credentials or compromised network paths cannot become a route into the vault.

Talk to Firevault about Disconnect to Protect® for your organisation.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Threat Analysis18 June 20264 min read

FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy