← All news

breach

FortiBleed: 73,000 Fortinet Firewall Credentials Leaked

2026-06-17

A single exposed server has spilled VPN credentials for 73,932 Fortinet and FortiGate firewalls, and the affected organisations read like a roll call of the global economy. Researcher Bob Diachenko found the trove first, with usernames, email addresses and plaintext passwords tied to Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec and, awkwardly, Fortinet itself.

Whoever ran the operation made no effort to clean up after themselves. The same server held bash histories, cron job output, scripts and connection strings, effectively documenting the entire campaign from start to finish.

The numbers are absurd

From those artefacts, Diachenko pulled out:

  • 1.16 billion credential attempts against 320,777 FortiGate targets
  • 2.1 billion attempts against 163,650 Microsoft SQL Server systems
  • A 45-GPU Hashtopolis cluster grinding through intercepted SSL VPN authentication hashes

Among the fully compromised victims, he says, is a Turkish NATO defence contractor whose classified documents were stolen.

One of the biggest Fortinet credential hauls on record

Hudson Rock, which analysed the dataset after receiving it from Diachenko, calls it one of the largest collections of compromised Fortinet credentials it has ever handled. It covers 21,632 domains across 194 countries, with India, the United States and Taiwan leading the device count. Telecoms, IT services, finance, government, healthcare and manufacturing dominate the victim profile, and the entries are helpfully annotated with industry, revenue and headcount, presumably so the operators could pick their next targets without having to think too hard about it.

Not brute-forced. Exported.

Kevin Beaumont independently verified portions of the data and confirmed it is real. He puts the figure closer to 75,000 devices, says most are still online running fairly recent FortiOS versions, and notes the credentials appear to have come from exported Fortinet configurations rather than brute-forced logins. That would explain why many of the passwords are long and genuinely complex, the kind of strings a password policy is meant to produce.

Based on Shodan, 75,000 devices is roughly half of every internet-accessible Fortinet firewall in existence. How the configurations were originally pulled, whether through a known CVE, an unreported one, or something stranger, is still unclear.

What to do if you run Fortinet gear

Hudson Rock has published a free lookup tool so administrators can check whether their devices appear in the dataset. The immediate hygiene is obvious enough:

  • Rotate VPN and admin credentials
  • Turn on multi-factor authentication everywhere it is available
  • Pull the management interface off the public internet

The harder question is the one nobody is answering yet: how did 75,000 device configurations walk out the door in the first place, and who else has a copy?

FortiBleed: 73,000 Fortinet Firewall Credentials Leaked | RiskSense