
FortiBleed: 86,644 firewalls breached in credential heist
A Russian-speaking initial access broker group has confirmed the compromise of 86,644 FortiGate firewalls and harvesting of over 110 million credentials in an active campaign researchers call FortiBleed, prompting urgent remediation guidance from U.S. federal cybersecurity authorities.
The campaign surfaced publicly on June 13, 2026, when researcher Volodymyr "Bob" Diachenko disclosed evidence of large-scale credential harvesting targeting Fortinet devices Shattered.io. On June 18, the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory directing organizations to disable internet-facing management interfaces, rotate all administrative credentials immediately, and apply the latest firmware updates Cloud Security Alliance.
Attack Scope and Attribution
The confirmed 86,644 devices with valid harvested credentials represent only part of the threat landscape. Threat researchers estimate the campaign scanned and targeted over 430,000 FortiGate firewalls globally across 194 countries Security Affairs. The attackers harvested credentials across 24 different protocols, totaling over 110 million usernames and passwords, according to analysis of 659+ harvesting pipelines.
Forensic indicators point to a financially motivated Russian-speaking initial access broker group, with evidence including Russian-language tool documentation and scheduling patterns aligned to Moscow time Shattered.io. The operation does not exploit a Fortinet product vulnerability. Instead, attackers employed brute-force attacks, credential stuffing, and abuse of the legitimate diagnostic command `diagnose sniffer packet` to extract credentials from device memory.
Technical Method and Secondary Threats
The campaign leverages a custom Golang-based tool called FortigateSniffer to automate reconnaissance and credential extraction across internet-facing management interfaces. Threat intelligence analysts have linked the harvested credentials to subsequent intrusions by ransomware operators including INC Ransom and Lynx, indicating the IAB group functions as a wholesale supplier of initial access Security Affairs. A NATO-aligned defense contractor has been confirmed as a high-profile breach victim.
Remediation Status
Fortinet stated it is "aware of reports of malicious cyber actors targeting Fortinet devices in a credential-harvesting campaign" and emphasized this is "not a Fortinet product vulnerability." As of July 2026, no court filings, criminal sentences, or law enforcement actions have been announced against the attributed threat group. The campaign remains active.
Organizations remain responsible for implementing the CISA-directed controls: disabling remote management access where possible, rotating administrative credentials, and deploying the latest device firmware to patch supporting weaknesses in authentication and logging.