---
title: "FortiBleed: 86,644 firewalls breached in credential heist"
slug: "fortibleed-86644-firewalls-breached-in-credential-heist"
published: "2026-07-16"
beat: "Crime"
tags: ["Crime", "Policy"]
creator: "Agentry Newsroom"
editor: "Susanne Sperling, Editor — Human in the Loop"
tools: ["Claude (Anthropic)", "Perplexity Sonar"]
creativeWorkStatus: "verified"
dateReviewed: "2026-07-16"
aiActArticle50: "compliant"
humanView: "https://agentry.news/fortibleed-86644-firewalls-breached-in-credential-heist"
agentView: "https://agentry.news/agent/fortibleed-86644-firewalls-breached-in-credential-heist"
---# FortiBleed: 86,644 firewalls breached in credential heist

> A Russian-speaking initial access broker group has confirmed compromises of 86,644 FortiGate firewalls across 194 countries and harvested over 110 million credentials via brute-force attacks, accordin

*Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. [AI policy](/ai-policy).*

A Russian-speaking initial access broker group has confirmed the compromise of **86,644 FortiGate firewalls** and harvesting of over **110 million credentials** in an active campaign researchers call **FortiBleed**, prompting urgent remediation guidance from U.S. federal cybersecurity authorities.

The campaign surfaced publicly on June 13, 2026, when researcher Volodymyr "Bob" Diachenko disclosed evidence of large-scale credential harvesting targeting Fortinet devices [Shattered.io](https://shattered.io/fortibleed-fortinet-86644-firewalls-2026/). On June 18, the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory directing organizations to **disable internet-facing management interfaces, rotate all administrative credentials immediately, and apply the latest firmware updates** [Cloud Security Alliance](https://labs.cloudsecurityalliance.org/research/csa-research-note-fortibleed-network-device-credential-harve/).

## Attack Scope and Attribution

The confirmed 86,644 devices with valid harvested credentials represent only part of the threat landscape. Threat researchers estimate the campaign **scanned and targeted over 430,000 FortiGate firewalls globally** across 194 countries [Security Affairs](https://securityaffairs.com/194645/security/430000-fortigate-devices-exposed-in-fortibleed-ransomware-link.html). The attackers harvested credentials across 24 different protocols, totaling over 110 million usernames and passwords, according to analysis of 659+ harvesting pipelines.

Forensic indicators point to a financially motivated Russian-speaking initial access broker group, with evidence including Russian-language tool documentation and scheduling patterns aligned to Moscow time [Shattered.io](https://shattered.io/fortibleed-fortinet-86644-firewalls-2026/). The operation does **not** exploit a Fortinet product vulnerability. Instead, attackers employed brute-force attacks, credential stuffing, and abuse of the legitimate diagnostic command `diagnose sniffer packet` to extract credentials from device memory.

## Technical Method and Secondary Threats

The campaign leverages a custom Golang-based tool called **FortigateSniffer** to automate reconnaissance and credential extraction across internet-facing management interfaces. Threat intelligence analysts have linked the harvested credentials to subsequent intrusions by ransomware operators including **INC Ransom** and **Lynx**, indicating the IAB group functions as a wholesale supplier of initial access [Security Affairs](https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html). A NATO-aligned defense contractor has been confirmed as a high-profile breach victim.

## Remediation Status

Fortinet stated it is "aware of reports of malicious cyber actors targeting Fortinet devices in a credential-harvesting campaign" and emphasized this is "**not** a Fortinet product vulnerability." As of July 2026, no court filings, criminal sentences, or law enforcement actions have been announced against the attributed threat group. The campaign remains **active**.

Organizations remain responsible for implementing the CISA-directed controls: disabling remote management access where possible, rotating administrative credentials, and deploying the latest device firmware to patch supporting weaknesses in authentication and logging.