title: "FortiBleed: 86,644 firewalls breached in credential heist" slug: "fortibleed-86644-firewalls-breached-in-credential-heist" published: "2026-07-16" beat: "Crime" tags: ["Crime", "Policy"] creator: "Agentry Newsroom" editor: "Susanne Sperling, Editor — Human in the Loop" tools: ["Claude (Anthropic)", "Perplexity Sonar"] creativeWorkStatus: "verified" dateReviewed: "2026-07-16" aiActArticle50: "compliant" humanView: "https://agentry.news/fortibleed-86644-firewalls-breached-in-credential-heist" agentView: "https://agentry.news/agent/fortibleed-86644-firewalls-breached-in-credential-heist"
A Russian-speaking initial access broker group has confirmed compromises of 86,644 FortiGate firewalls across 194 countries and harvested over 110 million credentials via brute-force attacks, accordin
Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.
A Russian-speaking initial access broker group has confirmed the compromise of 86,644 FortiGate firewalls and harvesting of over 110 million credentials in an active campaign researchers call FortiBleed, prompting urgent remediation guidance from U.S. federal cybersecurity authorities.
The campaign surfaced publicly on June 13, 2026, when researcher Volodymyr "Bob" Diachenko disclosed evidence of large-scale credential harvesting targeting Fortinet devices Shattered.io. On June 18, the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory directing organizations to disable internet-facing management interfaces, rotate all administrative credentials immediately, and apply the latest firmware updates Cloud Security Alliance.
The confirmed 86,644 devices with valid harvested credentials represent only part of the threat landscape. Threat researchers estimate the campaign scanned and targeted over 430,000 FortiGate firewalls globally across 194 countries Security Affairs. The attackers harvested credentials across 24 different protocols, totaling over 110 million usernames and passwords, according to analysis of 659+ harvesting pipelines.
Forensic indicators point to a financially motivated Russian-speaking initial access broker group, with evidence including Russian-language tool documentation and scheduling patterns aligned to Moscow time Shattered.io. The operation does not exploit a Fortinet product vulnerability. Instead, attackers employed brute-force attacks, credential stuffing, and abuse of the legitimate diagnostic command diagnose sniffer packet to extract credentials from device memory.
The campaign leverages a custom Golang-based tool called FortigateSniffer to automate reconnaissance and credential extraction across internet-facing management interfaces. Threat intelligence analysts have linked the harvested credentials to subsequent intrusions by ransomware operators including INC Ransom and Lynx, indicating the IAB group functions as a wholesale supplier of initial access Security Affairs. A NATO-aligned defense contractor has been confirmed as a high-profile breach victim.
Fortinet stated it is "aware of reports of malicious cyber actors targeting Fortinet devices in a credential-harvesting campaign" and emphasized this is "not a Fortinet product vulnerability." As of July 2026, no court filings, criminal sentences, or law enforcement actions have been announced against the attributed threat group. The campaign remains active.
Organizations remain responsible for implementing the CISA-directed controls: disabling remote management access where possible, rotating administrative credentials, and deploying the latest device firmware to patch supporting weaknesses in authentication and logging.