Two overlapping research efforts, dubbed FortiBleed, uncovered a large database of verified Fortinet firewall and VPN credentials, with SOCRadar reporting more than 30,000 devices and Hudson Rock separately documenting nearly 74,000 exposed firewall URLs across 194 countries.
Facts
| Field | Detail |
| Campaign name | FortiBleed |
| SOCRadar-reported device count | 30,791 verified credentials |
| Hudson Rock-reported device count | 73,932 unique firewall URLs, 21,632 domains |
| Countries affected | 194 |
| Credential source | Mostly prior Fortinet incidents, per researchers |
| Fortinet’s position | Says the data is a resharing of previously stolen secrets, not a new breach |
SOCRadar researchers discovered an exposed operational server belonging to a suspected Russian-speaking threat actor, giving them visibility into a credential-harvesting campaign targeting Fortinet firewalls and VPN gateways. In a report published June 16, 2026, SOCRadar said the attacker’s database held login credentials for more than 30,791 devices belonging to companies and government organizations across 194 countries, including banks, telecoms, hospitals, universities and energy companies.
Days later, security researcher Bob Diachenko independently found a separate exposed server containing what he described as a larger archive: 73,932 unique Fortinet and FortiGate firewall URLs across the same 194 countries, spanning 21,632 domains. Threat intelligence firm Hudson Rock analyzed the dataset after receiving it from Diachenko and confirmed the credentials as authentic and fairly recent, working with several named organizations to verify access. Researcher Kevin Beaumont separately corroborated portions of the data, noting that some devices sampled were running fairly recent patches, meaning patching alone had not blocked the exposure.

Figure 1. Independent researchers reported different counts of exposed credentials within days of each other.
Why old passwords still work
Researchers describe the credential list as curated rather than randomly brute-forced, built substantially from passwords exposed in earlier Fortinet-related incidents. Fortinet has said the database represents a resharing of secrets stolen in previous incidents combined with brute-forced data, rather than evidence of a new intrusion. Beaumont noted that Fortinet strengthened its password storage in early 2025 by moving to PBKDF2 with randomized salt, but many devices still rely on the older, more crackable SHA-256-with-salt method. The practical risk highlighted by both research teams is the same regardless of the exact figure: organizations that patched a Fortinet vulnerability years ago can still be exposed today if they never rotated the credentials tied to that device.
What organizations should do
Rotate all administrative and system-account credentials on internet-facing Fortinet devices, regardless of when the device was last patched. Enforce multi-factor authentication on management interfaces, and restrict FortiGate management access from the public internet where operationally possible. Hudson Rock has published a lookup tool organizations can use to check whether their credentials appear in the exposed dataset.

Leave a Reply