INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
FortiBleed Attackers Exploit Firewalls to Steal Credentials
| 2026-06-23 12:34 MEDIUM LOW DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
The FortiBleed attack campaign, which began at least in February 2026, is believed to be carried out by Russian threat actors using a sniffer tool dubbed FortigateSniffer that turns compromised FortiGate firewalls into passive credential collectors. The attackers have targeted more than 430,000 FortiGate firewalls globally and have resulted in the breach of high-value targets such as a NATO-aligned defense contractor. Small to medium-sized businesses with fewer than 200 employees, particularly in the US and India, are among the key targets of this campaign. As a result of the attack, attackers have managed to create over 659 credential-harvesting pipelines using FortigateSniffer, resulting in the theft of more than 110 million credentials, including RADIUS, NTLM, and Kerberos material.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign
BasedCampaign
Based
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
defensedefense
governmentgovernment
Incident Timeline
2026/06/23
Threat actors used FortigateSniffer to compromise hundreds of thousands of FortiGate firewalls, turning them into passive credential stealers.
Click on any entity below to view its context and source!
victims
200 employees
Key targets of the campaign are small to medium-sized businesses (SMBs) with fewer than 200 employees, particularly in the US and India, according to SOCRadar.
infrastructure
Fortigate
…Radar have unpacked the attack chain behind the ongoing threat campaign, which they believe is targeting more than 430,000
FortiGate firewalls
globally and has resulted in the breach of high-value targets such as a NATO-aligned defense contractor…
…d the global "
FortiBleed
" credential-harvesting campaign engineered a sniffer tool to compromise hundreds of thousands of FortiGate routers and turn them into passive stealers in a wave of attacks that's now known to be much broader than initiall…
"FortigateSniffer abuses the FortiOS built-in diagnostic command '-diagnose sniffer packet' to passively capture authentication traffic from compromised FortiGate firewalls," SOCRadar researchers wrote.
This is done by scanning the Internet for exposed
FortiGate firewalls
and other edge services, enriching the data with organization and revenue information, and ranking targets based on potential value.
…via Klue App Compromise
Once targets have been identified, attackers use credential-stuffing and brute-force attacks against FortiGate administrative interfaces and SSH services to obtain valid credentials and footholds on Internet-facing devices.
…otate all credentials tied to Fortinet VPN and administrative interfaces; enforce multifactor authentication (MFA); remove
FortiGate
management interfaces from direct Internet exposure; and review gateway and authentication logs for suspicious ac…
infrastructure
659 harvesting pipelines
FortiBleed Scope and Victimology
So far, attackers have managed to create 659 credential-harvesting pipelines using the tool and already have stolen more than 110 million
credentials
, including
RADIUS
, NTLM, and Kerberos material, SOCRadar found.
data_breach
110 credentials
FortiBleed Scope and Victimology
So far, attackers have managed to create 659 credential-harvesting pipelines using the tool and already have stolen more than 110 million
credentials
, including
RADIUS
, NTLM, and Kerberos material, SOCRadar found.
Tactical Metrics
Metrics
victims
200
Employees
Click for context!
Key targets of the campaign are small to medium-sized businesses (SMBs) with fewer than 200 employees, particularly in the US and India, according to SOCRadar.
Metrics
infrastructure
Fortigate
Affected Product
…Radar have unpacked the attack chain behind the ongoing threat campaign, which they believe is targeting more than 430,000
FortiGate firewalls
globally and has resulted in the breach of high-value targets such as a NATO-aligned defense contractor…
…d the global "
FortiBleed
" credential-harvesting campaign engineered a sniffer tool to compromise hundreds of thousands of FortiGate routers and turn them into passive stealers in a wave of attacks that's now known to be much broader than initiall…
"FortigateSniffer abuses the FortiOS built-in diagnostic command '-diagnose sniffer packet' to passively capture authentication traffic from compromised FortiGate firewalls," SOCRadar researchers wrote.
This is done by scanning the Internet for exposed
FortiGate firewalls
and other edge services, enriching the data with organization and revenue information, and ranking targets based on potential value.
…via Klue App Compromise
Once targets have been identified, attackers use credential-stuffing and brute-force attacks against FortiGate administrative interfaces and SSH services to obtain valid credentials and footholds on Internet-facing devices.
…otate all credentials tied to Fortinet VPN and administrative interfaces; enforce multifactor authentication (MFA); remove
FortiGate
management interfaces from direct Internet exposure; and review gateway and authentication logs for suspicious ac…
Metrics
infrastructure
659
Harvesting Pipelines
FortiBleed Scope and Victimology
So far, attackers have managed to create 659 credential-harvesting pipelines using the tool and already have stolen more than 110 million
credentials
, including
RADIUS
, NTLM, and Kerberos material, SOCRadar found.
Metrics
data_breach
110,000,000
Credentials
FortiBleed Scope and Victimology
So far, attackers have managed to create 659 credential-harvesting pipelines using the tool and already have stolen more than 110 million
credentials
, including
RADIUS
, NTLM, and Kerberos material, SOCRadar found.
Intelligence Sources
Dark Reading
2026-06-23
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T09:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
SMBs
entity
5x
tactic
Cyber Operation Type
Reconnaissance
tactic
3x
target region
Target Country
Russian Federation
country
2x
industry
Targeted Sector
Defense
sector
2x
attribution
Attributing Entity
FortiBleed
authority
Contextual Telemetry
Context Block
10 METRICS
victims
Employees
200
employees
infrastructure
Affected Product
Fortigate
software
general metric
Fortigate
430,000
fortigate
campaign
Campaign
Campaign
Based
operation
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
timeline
Temporal Reference
2026/06/16
date
general metric
Authentication Protocols
24
authentication protocols
infrastructure
Harvesting Pipelines
659
harvesting pipelines
data breach
Credentials
110,000,000
credentials
general metric
Countries
200
countries
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.