Introduction
The Fortinet firewall credential leak known as FortiBleed is one of the most significant network perimeter security events of 2026. In June 2026, threat actors compromised verified login credentials for over 86,644 internet-facing FortiGate firewalls and SSL VPN gateways spanning 194 countries. What makes this breach particularly alarming is that attackers did not need a new zero-day exploit to break in, they simply walked through the front door using stolen, unrotated passwords that organizations had never changed after previous incidents.
As a result, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory on June 18, 2026, calling on all Fortinet customers to take immediate hardening action. Consequently, organizations that have not yet addressed this Fortinet firewall credential leak are operating with an open door that threat actors are actively walking through. In this post, we break down exactly how FortiBleed unfolded, why so many devices were vulnerable, and most importantly, what your organization must do right now to close the gap.
What Is FortiBleed?FortiBleed is a large-scale Fortinet firewall credential leak discovered in June 2026 that exposed verified login credentials for over 86,000 internet-facing FortiGate firewalls and SSL VPN gateways across 194 countries. Threat actors used brute-force attacks, credential stuffing, and previously leaked passwords to gain administrative access to enterprise and government networks worldwide, without exploiting any new vulnerability. |
How the FortiBleed Attack Unfolded
To understand the full impact of this breach, it helps to trace how the attack actually worked, from initial scanning to lateral network infiltration. FortiBleed was not opportunistic. It was methodical, automated, and self-reinforcing.
How Attackers Targeted Fortinet Devices
Threat actors began by systematically scanning the internet for internet-facing FortiGate firewalls and SSL VPN gateways. Rather than exploiting a new vulnerability, they relied on a curated database of previously leaked Fortinet credentials, passwords from prior breaches that organizations had simply never rotated. This approach, known as credential stuffing, proved devastatingly effective. Automated scripts tested thousands of credential combinations per hour against exposed management interfaces, validating each successful login before adding it to a growing database of confirmed, working access credentials. This type of Fortinet firewall credential leak begins long before the first alert fires.
The Self-Feeding Attack Loop
Furthermore, once attackers gained access to a FortiGate firewall, they did not immediately announce their presence. Instead, they used the compromised device as a passive listening post, silently monitoring SSL VPN traffic flowing through it. As a result, additional credentials collected from this passive interception were fed back into the scanning engine to compromise even more devices. Therefore, this Fortinet firewall credential leak was not a one-time breach, it was a compounding, self-reinforcing operation that grew larger with every successful login.
Who Was Behind FortiBleed?
The National Cyber Security Centre (NCSC) described FortiBleed as a global campaign using brute-force, dictionary attack, and credential stuffing methods. Moreover, threat intelligence firm SOCRadar identified the attackers’ operational server, discovering not just a list of stolen passwords but the full attack infrastructure, including automation scripts and a victim database organized by country, sector, and organization revenue. According to SOCRadar, the campaign is believed to involve Russian-speaking threat actors, though attribution remains under active investigation.
The Scale of the Fortinet Firewall Credential Leak, By the Numbers
Before examining root causes, it is important to understand just how significant this exposure is. The numbers, in themselves, make an undeniable case for immediate action.
| 86,644
Fortinet devices compromised |
194
Countries affected |
35%
Generic admin accounts breached |
20%+
Enterprise orgs above $1B revenue impacted |
Additionally, according to SOCRadar’s analysis, generic admin accounts (35%) and built-in Fortinet system accounts (28.3%) together made up the majority of compromised credentials. This finding points directly to a widespread failure to rename default accounts or rotate factory credentials, giving attackers a highly reliable target list even before any brute-force effort was needed.
Why So Many Firewalls Were Vulnerable
FortiBleed did not succeed because Fortinet’s technology failed. It succeeded because organizations neglected basic credential hygiene practices. Consequently, this breach is a human and process failure as much as a technical one.
Default Credentials Left Unchanged
A significant portion of compromised devices were still using default or factory-set admin account names. Built-in Fortinet system accounts, which every FortiGate ships with, accounted for over 28% of all breached credentials. Renaming or disabling these accounts is a foundational step in firewall hardening, yet thousands of organizations across 194 countries skipped it entirely.
Weak Credential Storage, Legacy Hashing
CISA’s advisory specifically highlighted that many affected organizations were still storing administrator credentials using weak, legacy hashing algorithms rather than the more secure Password-Based Key Derivation Function 2 (PBKDF2) standard. As a result, when attackers gained access to configuration files, cracking stored password hashes became relatively straightforward, further compounding the damage from this Fortinet firewall credential leak.
Internet-Exposed Management Interfaces
One of the most critical factors enabling FortiBleed was the widespread practice of leaving Fortinet firewall management interfaces directly accessible from the public internet. Port 443, the standard HTTPS port and default for Fortinet SSL VPN interfaces, dominated the attack data. Additionally, non-standard ports such as 4443, 8443, and 10443 were also swept, confirming that attackers configured their scanners to cover all common Fortinet deployment variants.
Credential Reuse from Prior Breaches
Perhaps the most troubling finding from SOCRadar’s investigation is that many of the passwords used in this campaign were sourced from previous Fortinet security incidents, breaches that organizations had already experienced but had not fully remediated. In other words, the attackers were counting on organizations failing to rotate credentials after prior incidents. That bet paid off at massive scale.
What CISA Is Telling Organizations to Do Right Now
In response to the Fortinet firewall credential leak campaign, CISA issued a formal advisory on June 18, 2026, outlining specific immediate actions for all organizations running FortiGate firewalls or Fortinet SSL VPN gateways. Therefore, if your organization uses Fortinet products, the following steps are not optional, they are urgent.
- Terminate all active SSL VPN and administrative sessions immediately. Do not wait, active sessions may already be monitored by attackers.
- Reset all Fortinet VPN and administrative passwords, especially on any system accessible from the public internet. Enforce strong, unique password policies across all accounts.
- Migrate to PBKDF2 credential storage. Remove any legacy hashing configurations from all FortiGate devices to prevent credential cracking in the event of future configuration file exposure.
- Review firewall, VPN, authentication, and domain controller logs for signs of unauthorized configuration changes, suspicious logins, or lateral movement activity.
- Enable phishing-resistant MFA on all external-facing gateways. Password-only access to network perimeter devices is no longer an acceptable risk posture.
- Restrict management interfaces from public internet access. Firewall administration panels should never be reachable from external IP addresses without a dedicated, monitored access pathway.
- Remove unauthorized accounts and conduct a full audit of all admin-level access credentials across every Fortinet device in your environment.
Is Your Fortinet Firewall Affected by the Credential Leak?
How to Check If Your Fortinet Device Is Affected?Hudson Rock has published a free FortiBleed lookup tool that allows organizations to check whether their Fortinet devices appear in the compromised credential database. Security researcher Kevin Beaumont confirmed that the credentials in the leak are legitimate, valid, and that most affected devices remain online, meaning exposure is active, not historical. |
Beyond the lookup tool, several signs within your own environment may indicate compromise from the FortiBleed campaign:
- Unexpected configuration changes on FortiGate devices, particularly changes to admin accounts, routing rules, or VPN settings
- Unfamiliar admin account names or newly created accounts not provisioned by your team
- Unusual SSL VPN session activity, particularly logins from unexpected geographic locations or IP ranges
- Anomalous outbound traffic from firewall devices, which may indicate passive credential harvesting is underway
- Authentication log gaps or log tampering, which may indicate an attacker has attempted to cover their tracks
Importantly, even if your credentials do not appear in the current FortiBleed database, that does not mean your environment is secure. As security researcher Kevin Beaumont noted, the leaked data appears to be recent, and the campaign remains active. Consequently, organizations should treat Fortinet firewall credential leak remediation as an ongoing program, not a one-time cleanup task.
Firewall Hardening, What a Professional Audit Covers?
CISA’s advisory lays out the immediate response steps. However, a genuine Fortinet firewall security audit goes significantly further than a one-time password reset. Organizations that have experienced a Fortinet firewall credential leak, or want to prevent one, need a structured, repeatable process that addresses their full perimeter security posture.
- External Attack Surface Assessment: Mapping all internet-facing Fortinet devices, exposed ports, and management interfaces to identify what is reachable from outside your network perimeter.
- Credential Hygiene Review: Auditing all admin accounts, identifying default or unchanged usernames, verifying password strength policies, and confirming PBKDF2 hashing is in use across all devices.
- Configuration and Policy Review: Examining firewall rules, SSL VPN policies, routing configurations, and access control lists for misconfigurations, outdated rules, and unnecessarily permissive policies.
- MFA and Access Control Validation: Confirming that phishing-resistant multi-factor authentication is enforced consistently across all external gateways and administrative access paths.
- Log Review and Threat Hunting: Analyzing authentication logs, VPN session records, and configuration change history for indicators of compromise or unauthorized activity.
- Patch and Vulnerability Status: Verifying that all Fortinet devices are running current firmware and that known exploited vulnerabilities tracked in CISA’s KEV catalog have been fully remediated.
One-Time Cleanup vs. Continuous Firewall Audit Program
The table below illustrates why a one-time remediation pass is insufficient for organizations seeking durable protection against credential-based attacks like FortiBleed:
| Security Area | One-Time Cleanup | Continuous Audit Program |
| Credential Rotation | One-time, manual | Scheduled, automated, verified |
| Log Review | After-incident only | Continuous 24/7 monitoring |
| MFA Enforcement | Often inconsistent | Policy-driven across all gateways |
| Patch Status | Reactive | Proactive, tracked per CVE |
| Attack Surface Visibility | Limited | Full external exposure mapping |
| Incident Response | Ad hoc | Documented playbooks, tested regularly |
| Compliance Alignment | Unclear | Mapped to ISO 27001, NIST, SOC 2 |
How Cyberix Helps Organizations Respond to the Fortinet Firewall Credential Leak
Cyberix is a Washington, D.C.-based Cybersecurity Services Provider (CSSP) with deep expertise in protecting enterprise and government networks against exactly the type of credential-based, perimeter-targeting attacks that FortiBleed represents. Organizations across financial services, federal government, and critical infrastructure turn to Cyberix when they need more than a checklist, they need a partner with the technical depth to find what others miss.
Cyberix holds industry-leading certifications including ISO 27001, ISO 27032, SOC 2 Type II, CISSP, CASP+, and SISA, credentials that reflect decades of red team and blue team expertise applied across high-stakes environments. Furthermore, Cyberix’s practitioners have operated at the intersection of threat intelligence, incident response, and network security, giving them a uniquely practical perspective on how attackers exploit credential weaknesses at scale.
Relevant Cyberix Services for FortiBleed Remediation
- Attack Surface Management: Cyberix continuously maps your external-facing infrastructure, including all Fortinet devices, VPN gateways, and management interfaces, to identify exposure before attackers do. Consequently, your team receives actionable intelligence rather than a static, point-in-time snapshot.
- Vulnerability Management: Beyond patch scanning, Cyberix prioritizes vulnerabilities by real-world exploitability, tracking CISA’s Known Exploited Vulnerabilities catalog and mapping your environment’s exposure against active campaigns like FortiBleed.
- Virtual SOC (Security Operations Center): Cyberix’s 24/7 Virtual SOC provides continuous monitoring of your network perimeter, including real-time detection of credential misuse, unauthorized access attempts, and lateral movement indicators, the exact activity that a Fortinet firewall credential leak enables.
Speak with a Cyberix ExpertIf your organization uses Fortinet FortiGate firewalls or SSL VPN gateways, do not wait for a breach notification to prompt action. Speak with a Cyberix expert today to assess your firewall security posture and close the gaps that FortiBleed is actively exploiting. |
Conclusion
The Fortinet firewall credential leak known as FortiBleed is not merely another data breach headline. It is a direct demonstration of how organizations’ most trusted network security devices can be turned against them when basic credential hygiene is neglected. The fact that attackers compromised over 86,000 devices across 194 countries without needing a single new exploit is sobering. It means that the most important security control in this case was not a patch, it was a password rotation that never happened.
Three core takeaways stand out from the FortiBleed incident:
- Credential reuse and unrotated default accounts are among the highest-impact vulnerabilities in any environment relying on perimeter security devices.
- Internet-exposed firewall management interfaces dramatically expand your attack surface and must be locked down immediately.
- One-time remediation is not a security program. Continuous monitoring, regular audits, and proactive attack surface management separate organizations that contain incidents from those that become the incident.
If your organization runs Fortinet infrastructure, now is the time to act. Cyberix’s security team is ready to help you assess your exposure, harden your Fortinet environment, and implement continuous protection against the credential-based attacks that FortiBleed has proven are both widespread and ongoing. Speak with a Cyberix expert today, before attackers find the open door first.
Frequently Asked Questions, Fortinet Firewall Credential Leak & FortiBleed
1. What is a Fortinet firewall credential leak?
A Fortinet firewall credential leak occurs when login credentials for FortiGate firewalls or Fortinet SSL VPN gateways are exposed, stolen, or compromised, allowing unauthorized parties to gain administrative access to an organization’s network perimeter. The FortiBleed campaign is the largest known example of this type of credential exposure, affecting over 86,000 devices across 194 countries in June 2026.
2. Am I affected if I use FortiGate or Fortinet SSL VPN?
If your organization runs internet-facing FortiGate firewalls or Fortinet SSL VPN gateways, you are potentially affected. Organizations should use Hudson Rock’s free FortiBleed lookup tool to check whether their devices appear in the compromised database and should take CISA’s recommended hardening steps regardless of lookup results, since the campaign remains active.
3. How did attackers get into Fortinet firewalls without a new vulnerability?
FortiBleed exploited credential reuse and poor password hygiene rather than a new software vulnerability. Attackers used curated lists of previously leaked Fortinet passwords, many of which organizations had never rotated after prior incidents, and tested them automatically against internet-exposed management interfaces. In many cases, default account names were still in use, making the process even more efficient for attackers, making this type of Fortinet firewall credential leak entirely preventable.
4. What should I do immediately if my firewall credentials were leaked?
Follow CISA’s June 18, 2026 advisory: terminate all active SSL VPN and administrative sessions, reset all Fortinet passwords immediately, enable phishing-resistant MFA, migrate to PBKDF2 credential storage, review logs for unauthorized activity, and restrict management interfaces from public internet access. Additionally, contact a cybersecurity partner like Cyberix to conduct a full firewall audit if your internal team lacks the capacity to verify remediation thoroughly.
5. How does a credential stuffing attack work on firewalls?
A credential stuffing attack involves taking username and password combinations from previous data breaches and automatically testing them against a target system. In the case of FortiBleed, attackers compiled credentials from prior Fortinet incidents and ran them against internet-exposed FortiGate management interfaces at scale. Consequently, any device running unchanged, previously exposed credentials was automatically added to the attacker’s verified access database.
6. What is PBKDF2 and why does CISA recommend it?
PBKDF2, or Password-Based Key Derivation Function 2, is a secure method for storing hashed passwords that makes brute-force cracking significantly more computationally expensive. CISA recommended it specifically because older Fortinet configurations may store admin credentials using weaker legacy hashing algorithms. Upgrading to PBKDF2 ensures that even if an attacker obtains configuration files, cracking stored credentials becomes far more difficult.
7. How often should organizations audit their Fortinet firewall configurations?
A one-time audit is insufficient for sustained protection. Best practice is to conduct a formal firewall configuration review at least quarterly, combined with continuous monitoring through a Security Operations Center or managed security service. Furthermore, any time a significant Fortinet vulnerability is disclosed or a campaign like FortiBleed is identified, an out-of-cycle audit should be triggered immediately.












