FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices

Fortinet’s FortiGate VPN credentials for about 73,932 firewall URLs across 194 countries were exposed in a data leak dubbed “FortiBleed.” Investigators say the data may come from Fortinet configurations and implicates a Russian-speaking multi-operator group that allegedly conducted billions of credential attempts against FortiGate targets and SQL Server systems. Many affected devices remain online with management interfaces exposed to the internet. Experts urge immediate password rotation, MFA enforcement, and gateway log monitoring; Hudson Rock offers a FortiBleed lookup tool to check exposure.

TechLogHub
June 17, 2026
4 min read
0 views

Share Article

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices

FORTIBLEED: FORTINET VPN CREDENTIALS LEAK EXPOSES THOUSANDS OF FORTIGATE DEVICES

OVERVIEWA major data leak known as FortiBleed has surfaced, reportedly exposing Fortinet and FortiGate VPN credentials for tens of thousands of firewall devices worldwide. Investigations indicate a repository containing usernames, email addresses, and plaintext passwords tied to Fortinet SSL VPN and FortiGate management interfaces. The leak has drawn attention from researchers who describe it as one of the largest known troves of Fortinet-related credentials.

HOW THE DISCOVERY UNFOLDED

  • The initial discovery was made by security researcher Bob Diachenko, who found a server hosting what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords.
  • Diachenko stated that the dataset includes entries for a broad set of organizations and industries, with many domain names and corresponding credentials.
  • Public postings from Diachenko described a large warehouse of artifacts, including domain lists and credential data, left exposed in an open directory.
  • Independent researchers later published analyses that corroborated the authenticity of portions of the data and provided context about how it may have been obtained and used.

WHAT THE DATA CONTAINS

  • Fortinet/FortiGate credentials: admin usernames and plaintext passwords, sometimes paired with email addresses.
  • Additional metadata: organization names, industry tags, revenue figures, and employee counts included within the dataset’s annotations.
  • Exposed artifacts: configuration-related strings, connection details, tooling, scripts, and logs observed in the same exposed directory.

SCOPE AND REACH

  • Unique firewall URLs: 73,932
  • Affected countries: 194
  • Unique domains referenced in the dataset: approximately 21,632 (with some reports noting around 21,634 domains in related dumps)
  • FortiGate targets analyzed: hundreds of thousands of devices
  • Fortinet-related exposure magnitude: described by researchers as among the largest collections of compromised Fortinet credentials to date
  • Targeted services: FortiGate SSL VPN interfaces and Fortinet management endpoints

NOTABLE ORGANIZATIONS IMPACTED (AS REPORTED IN THE DATASET)

  • Large multinational corporations across various sectors, including technology, manufacturing, telecommunications, and financial services
  • Notable names mentioned in analyses include Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and various government entities
  • The dataset reportedly included entries tied to a Turkish NATO defense contractor and other critical infrastructure operators
  • Government agencies and healthcare, educational, and manufacturing institutions appeared within the exposed records

HOW ATTACKERS OPERATED, ACCORDING TO EARLY ANALYSIS

  • The data reportedly reflects credentials used to authenticate Fortinet SSL VPNs and FortiGate devices.
  • Researchers documented a high volume of credential-authentication attempts, with hundreds of millions of attempts recorded across FortiGate targets and SQL Server systems.
  • Analysts indicated that attackers may have intercepted SSL VPN authentication hashes, cracked them with substantial GPU resources, and used recovered credentials to move laterally within Active Directory environments.
  • The operational narrative suggests a multi-operator threat group, described as Russian-speaking, was involved in harvesting and testing Fortinet credentials.

INDIVIDUAL EXPERT INSIGHTS

  • Bob Diachenko: Emphasized the scale of the exposed data, the diversity of organizations, and the likelihood that the credentials originated from Fortinet configurations or related tooling inadvertently left accessible.
  • Kevin Beaumont: Independently reviewed portions of the data and confirmed some admin logins and passwords as authentic. He suggested the dataset likely originated from exported Fortinet configurations and noted that many affected devices appeared to be online and running relatively recent FortiOS versions.
  • Hudson Rock: Analyzed the dataset and published a detailed report describing the scope, including the number of unique firewall URLs, domains, and the breadth of industries affected. They also released a FortiBleed lookup tool to help organizations check exposure.

ORIGIN AND UNANSWERED QUESTIONS

  • The precise method by which the configuration data was obtained remains unknown. Possibilities discussed by researchers include exploitation of vulnerabilities, information leaked from compromised devices, or errors in data handling that exposed configuration content.
  • While some credentials appear authentic, the exact provenance of the data—and whether all entries are valid or up-to-date—continues to be evaluated by researchers and affected vendors.
  • Comparisons to prior Fortinet-related leaks indicate this incident involves a broader set of devices and newer data than previous disclosures.

PUBLIC TOOLING AND ACCESSIBILITY

  • A FortiBleed lookup tool has been released to help organizations determine if they are included in the exposed dataset. This tool is offered as a resource for rapid verification of exposure status.
  • Public analyses and dashboards from researchers provide context on geographic distribution, industry sectors, and the scale of compromised assets.

IMPACT AND IMPLICATIONS

  • The leak underscores the risk of credentials associated with VPNs and remote access devices being exposed in plaintext or inadequately protected datasets.
  • The breadth of affected sectors and the presence of critical infrastructure operators highlight potential security implications for incident response, threat intelligence, and defense in depth.
  • Researchers emphasize the importance of recognizing patterns of exposure, monitoring for suspicious activity on Fortinet endpoints, and understanding that attackers may rotate through a large pool of compromised credentials.

RESEARCHERS’ SUMMARY AND TAKEAWAYS

  • The dataset represents a significant collection of Fortinet-related credentials and related artifacts that surfaced from an exposed server.
  • The findings point to a potentially sophisticated operation with a focus onFortinet SSL VPN devices and FortiGate appliances.
  • Independent analyses converge on the view that this incident is recent, geographically widespread, and associated with a large number of organizations spanning multiple industries.

CLOSING OBSERVATIONS

  • Fortinet-related configurations and credentials have been targeted in highly organized efforts, and the FortiBleed incident serves as a stark reminder of the ongoing risk to VPN-access devices.
  • The collaboration among researchers and the public release of tools to check exposure reflect a broader effort to illuminate the scope of the leak and assist organizations in assessing their risk.
  • As investigations continue, more details about the method of data acquisition and the full impact are expected to emerge, contributing to a clearer understanding of the incident and its implications for Fortinet deployments worldwide.

Stay Updated

Get the next deep dive in your inbox

Subscribe for product analysis, engineering explainers, and practical guides published on TechLogHub.

See what launched this week

One email a week: new and trending developer tools, fresh comparisons, and what shipped. Unsubscribe in one click.

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices | TechLogHub