Cybersecurity specialists revealed this week that hackers have compromised tens of thousands of Fortinet firewalls and VPNs worldwide in an ongoing campaign dubbed “FortiBleed”, exploiting recycled credentials rather than software vulnerabilities.
How the FortiBleed Attack Works
The widespread hacking campaign targets a surprisingly basic security oversight: organisations failing to change default firewall passwords or reusing credentials that have already been leaked online. Rather than deploying sophisticated zero-day exploits, the threat actors are utilising automated tools to scan the internet for exposed Fortinet devices.
Once an exposed firewall or VPN gateway is identified, the attackers gain access by testing databases of previously leaked passwords. According to reports published this week by threat intelligence firms Hudson Rock and SOCRadar, this initial breach allows the cybercriminals to harvest even more sensitive data from the victimised networks.
“Once a device is compromised, [the hackers] use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself,” SOCRadar noted in its analysis.
Fortinet Addresses the Credential-Harvesting Campaign
Fortinet spokesperson Tiffany Curci stated that the network security giant “is aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways.” Following its internal investigation, Fortinet asserted that the compromised data appears to be “a resharing of data from previous incidents, as well as bruteforcing of credentials, and is not related to any recent incident or advisory.”
However, the estimated scale of the campaign varies between the two security firms. Hudson Rock reported evidence suggesting that more than 73,000 unique Fortinet URLs have been compromised, whilst SOCRadar estimated the total number of breached devices to be just over 30,000.
Global Blue-Chip Companies Affected
The list of multinational corporations allegedly caught up in the FortiBleed campaign includes major household names. According to Hudson Rock, credentials belonging to Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC were found within the compromised datasets.
When contacted for comment, a Lenovo spokesperson acknowledged receiving the enquiry but did not provide a formal response. None of the other named corporations responded to requests for comment.
Geographic and Industry-Wide Impact
While the threat intelligence firms confirm that victims are scattered globally, the highest concentration of compromised devices is located in India, the United States, Taiwan, and Mexico. The campaign has heavily impacted critical sectors, with IT services, construction materials, and telecommunications firms identified as the primary targets by Hudson Rock. Furthermore, SOCRadar confirmed that several government agencies have also been breached. Both security firms attribute the campaign to a Russian-speaking cybercrime group.
Verification of the Leaked Data
The campaign was first reported by independent security researcher Bob Diachenko. Following the initial discovery, cybersecurity expert Kevin Beaumont analysed the leaked dataset and said in a blog post that he could confirm the data “is legit.”
While historical campaigns targeting Fortinet systems have relied on complex software vulnerabilities, this latest wave of attacks highlights the persistent threat of basic credential stuffing, proving that simple security hygiene remains a critical weak point for global enterprises.
