A massive cyber campaign named ‘FortiBleed’ has targeted more than 320,000 Fortinet firewall devices globally, compromising thousands of administrative credentials. Security researchers confirmed that attackers successfully verified 75,000 working credentials against administrative and SSL VPN interfaces.
The security incident has affected several major multinational corporations, including Samsung, Oracle, Spotify, and Sony. Researcher Volodymyr “Bob” Diachenko first surfaced the data, which was subsequently analyzed by cybersecurity firms Hudson Rock and SOCRadar using data from the Hunt Intelligence, Inc. feed.
The Mechanics of the FortiBleed Campaign
Specifically, the operation runs as a self-feeding loop where attackers scan the internet for exposed systems. They test each device against a curated list of passwords leaked from earlier breaches and infostealer logs. Once a login succeeds, the compromised device is turned into a listening post to sniff traffic and harvest fresh credentials.
As a result, these newly harvested credentials are fed directly back into the automated scanner to target more systems. This continuous cycle allows the attackers to expand their database of verified credentials rapidly without requiring manual intervention for each target.
Scale of the Fortinet firewall devices Attack
Notably, the scale of the campaign targeting Fortinet firewall devices is exceptionally large. The threat actors executed an estimated 1.16 billion credential attempts against the 320,000 targets. Additionally, they launched 2.1 billion brute-force attempts against 160,000 MSSQL servers.
During deeper network intrusions, the attackers intercept SSL VPN authentication hashes. These hashes are then cracked using a dedicated 45-GPU cluster, allowing the actors to move laterally into internal Active Directory systems. This method grants them deep access to corporate networks.
Global Impact and Compromised Networks
Meanwhile, Diachenko confirmed full network compromises across multiple countries, including Japan, Taiwan, Vietnam, Iraq, and Turkey. In Turkey, a NATO defense contractor was compromised, resulting in the theft of classified defense documents. This highlights the severe geopolitical implications of the campaign.
Moreover, the targeting of high-profile corporate networks indicates that the attackers are focusing on high-value assets. The compromised credentials allow persistent access to sensitive internal communications and proprietary corporate data across these international regions.
Recommended Remediation Steps
Consequently, organizations utilizing Fortinet firewall devices are advised to take immediate protective measures. Security experts recommend rotating all VPN and administrative credentials and enforcing multi-factor authentication (MFA) on all external gateways.
Furthermore, administrators should restrict management access to approved sources, segment internal networks, and audit gateway logs for unusual logins. Hudson Rock has also provided a free domain lookup tool to help organizations check for exposure.
Source: X (@IntCyberDigest)





