Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

Researchers say a leak exposed admin credentials for 73,932 Fortinet firewalls

The campaign, dubbed FortiBleed, allegedly cracked SSL VPN credentials across 194 countries; Fortinet had not publicly responded as of June 18.

Dmytro Spodarets
Jun 18, 2026 · 2 min read

Security researchers say an accidentally exposed server held cracked administrator credentials for 73,932 Fortinet FortiGate firewalls across 194 countries, a leak now circulating under the name FortiBleed. Researcher Volodymyr (Bob) Diachenko, who found the server, disclosed the exposure on June 17. Fortinet had not publicly responded as of June 18, and there is no official Fortinet advisory confirming the findings.

The data was analyzed by threat-intelligence firm Hudson Rock, which reported 73,932 unique firewall URLs and 21,632 unique domains in the set, naming affected organizations including Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, and Oracle, alongside government agencies and critical-infrastructure operators. Independent analyst Kevin Beaumont said he confirmed that some admin logins and passwords are real and still valid, and estimated that roughly half of all internet-accessible Fortinet firewalls are affected. Those scope estimates are researcher assessments, not vendor-confirmed figures.

According to Diachenko, a Russian-speaking, multi-operator group ran about 1.16 billion credential attempts against 320,777 FortiGate targets and 2.1 billion attempts against 163,650 Microsoft SQL Server systems. The researchers describe a method in which attackers intercepted SSL VPN authentication hashes, cracked them on a 45-GPU cluster managed with Hashtopolis, then used the recovered credentials to move laterally into Active Directory environments. Diachenko says at least four organizations were fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly exfiltrated.

The claims rest on researcher analysis rather than a vendor investigation, and a central question is unresolved: how the original FortiGate configurations were obtained. The researchers say that could trace to a previously known Fortinet vulnerability, a new flaw, or another method, and that the source remains unknown.

Hudson Rock has published a free FortiBleed lookup tool that organizations can use to check whether their devices appear in the dataset. The most affected countries are India, the United States, Taiwan, Mexico, and Turkey, with telecom, IT services, financial services, government, healthcare, education, and manufacturing among the hardest-hit sectors. A Fortinet advisory or a U.S. addition to the Known Exploited Vulnerabilities catalog could still follow.


Dmytro Spodarets
Dmytro Spodarets
Founder & Editor-in-Chief

Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.

More news