INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russian Hackers Exploit FortiBleed Vulnerability to Harvest Credentials
| 2026-06-22 10:25 MEDIUM LOW DATA BREACH
Executive Summary
AI-generated
On June 22, 2026, a large-scale Russian credential-harvesting operation known as FortiBleed targeted over 430,000 FortiGate devices globally, resulting in the theft of more than 110 million credentials. The campaign is believed to be financially motivated and has already led to confirmed breaches, including one involving a NATO-aligned defense contractor. The attackers used a five-phase attack chain that included credential sourcing, mass reconnaissance, initial access through SSH brute-force and credential stuffing, and lateral movement using a Golang-based tool called FortigateSniffer. This tool abuses legitimate diagnostic commands to capture authentication traffic without deploying malware, with the sniffer only running during normal business hours in Moscow Time. The campaign is still actively sniffing over 19,000 devices as of the time of writing, part of a broader pool of 80,553 identified targets.
Technical Mitigations AI-generated
• Password Policies (ATT&CK mitigation for Credential Stuffing): Refer to NIST guidelines when creating password policies.
• User Account Management (ATT&CK mitigation for Credential Stuffing): Proactively reset accounts that are known to be part of breached credentials either immediately, or after detecting bruteforce attempts.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
va•••••.ai
so•••••.io
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation
FortiBleedOperation
FortiBleed
Target & Sectors
EUROPE
EUROPE
MIDDLE_EAST
MIDDLE_EAST
LATAM
LATAM
NORTH_AMERICA
NORTH_AMERICA
technologytechnology
Incident Timeline
2026/06/22
Threat actors used a combination of tools, including Masscan and custom Shodan_Recon tool, to target 430,000+ FortiGate devices globally.
Click on any entity below to view its context and source!
infrastructure
Fortigate
FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
FortiBleed targeted 430,000+ FortiGate devices, harvesting 110M credentials and enabling breaches through large-scale credential theft.
The numbers alone are staggering: over 430,000 FortiGate firewalls targeted, more than 110 million credentials identified across 659+ harvesting pipelines, and a confirmed breach of a NATO-aligned defense contractor.
…with credential sourcing and mass reconnaissance, using Masscan for port sweeps, a custom Shodan_Recon tool for passive enrichment, and a purpose-built FortiProbe-fast binary to filter confirmed FortiGate devices from millions of raw scan results.
Initial access comes through SSH brute-force using 16 wordlists specifically curated for FortiGate admin account naming conventions, alongside credential stuffing against SSL-VPN portals.
FortiBleed is a large-scale, financially motivated campaign targeting FortiGate firewalls globally.
…ns potentially in scope immediately rotate all credentials tied to Fortinet VPN and administrative interfaces, enforce MFA, remove FortiGate management interfaces from direct internet exposure, and review authentication logs for anomalous activity.
financial
430,000 devices
FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
FortiBleed targeted 430,000+ FortiGate devices, harvesting 110M credentials and enabling breaches through large-scale credential theft.
data_breach
110 credentials
FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
FortiBleed targeted 430,000+ FortiGate devices, harvesting 110M credentials and enabling breaches through large-scale credential theft.
The numbers alone are staggering: over 430,000 FortiGate firewalls targeted, more than 110 million credentials identified across 659+ harvesting pipelines, and a confirmed breach of a NATO-aligned defense contractor.
infrastructure
659 pipelines
The numbers alone are staggering: over 430,000 FortiGate firewalls targeted, more than 110 million credentials identified across 659+ harvesting pipelines, and a confirmed breach of a NATO-aligned defense contractor.
infrastructure
Linux
The pentest lab environment itself runs seven Kali Linux virtual machines under QEMU/KVM, hardened with strict IPTables rules and designed for multi-operator remote access through shared tmux sessions.
infrastructure
150 additional servers
…a single exposed directory flagged by security researcher Volodymyr “Bob” Diachenko, STRU
traced the operation
to more than 150 additional servers, building a near-complete picture of the actor’s infrastructure, tooling, and operational workflow.
infrastructure
19,000 devices
At the time of writing, the campaign is still actively sniffing over 19,000 devices, part of a broader pool of 80,553 identified targets.
victims
80,553 identified targets
At the time of writing, the campaign is still actively sniffing over 19,000 devices, part of a broader pool of 80,553 identified targets.
victims
200 employees
Who is being hit
The victim profile skews heavily toward SMBs: roughly 66% of affected organizations have fewer than 200 employees, and nearly 90% have annual revenues below $100 million.
Tactical Metrics
Metrics
infrastructure
Fortigate
Affected Product
Click for context!
FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
FortiBleed targeted 430,000+ FortiGate devices, harvesting 110M credentials and enabling breaches through large-scale credential theft.
The numbers alone are staggering: over 430,000 FortiGate firewalls targeted, more than 110 million credentials identified across 659+ harvesting pipelines, and a confirmed breach of a NATO-aligned defense contractor.
…with credential sourcing and mass reconnaissance, using Masscan for port sweeps, a custom Shodan_Recon tool for passive enrichment, and a purpose-built FortiProbe-fast binary to filter confirmed FortiGate devices from millions of raw scan results.
Initial access comes through SSH brute-force using 16 wordlists specifically curated for FortiGate admin account naming conventions, alongside credential stuffing against SSL-VPN portals.
FortiBleed is a large-scale, financially motivated campaign targeting FortiGate firewalls globally.
…ns potentially in scope immediately rotate all credentials tied to Fortinet VPN and administrative interfaces, enforce MFA, remove FortiGate management interfaces from direct internet exposure, and review authentication logs for anomalous activity.
Metrics
financial
430,000
Devices
FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
FortiBleed targeted 430,000+ FortiGate devices, harvesting 110M credentials and enabling breaches through large-scale credential theft.
Metrics
data_breach
110,000,000
Credentials
FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
FortiBleed targeted 430,000+ FortiGate devices, harvesting 110M credentials and enabling breaches through large-scale credential theft.
The numbers alone are staggering: over 430,000 FortiGate firewalls targeted, more than 110 million credentials identified across 659+ harvesting pipelines, and a confirmed breach of a NATO-aligned defense contractor.
Metrics
infrastructure
659
Pipelines
The numbers alone are staggering: over 430,000 FortiGate firewalls targeted, more than 110 million credentials identified across 659+ harvesting pipelines, and a confirmed breach of a NATO-aligned defense contractor.
Metrics
infrastructure
Linux
Affected Product
The pentest lab environment itself runs seven Kali Linux virtual machines under QEMU/KVM, hardened with strict IPTables rules and designed for multi-operator remote access through shared tmux sessions.
Metrics
infrastructure
150
Additional Servers
…a single exposed directory flagged by security researcher Volodymyr “Bob” Diachenko, STRU
traced the operation
to more than 150 additional servers, building a near-complete picture of the actor’s infrastructure, tooling, and operational workflow.
Metrics
infrastructure
19,000
Devices
At the time of writing, the campaign is still actively sniffing over 19,000 devices, part of a broader pool of 80,553 identified targets.
Metrics
victims
80,553
Identified Targets
At the time of writing, the campaign is still actively sniffing over 19,000 devices, part of a broader pool of 80,553 identified targets.
Metrics
victims
200
Employees
Who is being hit
The victim profile skews heavily toward SMBs: roughly 66% of affected organizations have fewer than 200 employees, and nearly 90% have annual revenues below $100 million.
Intelligence Sources
Security Affairs
2026-06-22
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:06
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
an Active Russian Credential-Harvesting Operation
entity
5x
tactic
Cyber Operation Type
Lateral Movement
tactic
4x
target region
Target Country
Russian Federation
country
3x
target region
Target Region
MIDDLE_EAST
region
2x
infrastructure
Affected Product
Fortigate
software
2x
attribution
Attributing Entity
SOCRadar’s Threat Research Unit
authority
2x
general metric
%
66
%
Contextual Telemetry
Context Block
13 METRICS
campaign
Campaign
Operation
FortiBleed
operation
financial
Devices
430,000
devices
data breach
Credentials
110,000,000
credentials
industry
Targeted Sector
Defense
sector
general metric
Fortigate Firewalls
430,000
fortigate firewalls
infrastructure
Pipelines
659
pipelines
general metric
Wordlists
16
wordlists
timeline
Temporal Reference
2026
date
infrastructure
Additional Servers
150
additional servers
general metric
Protocols
24
protocols
infrastructure
Devices
19,000
devices
victims
Identified Targets
80,553
identified targets
victims
Employees
200
employees
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.