FortiBleed: Attack on FortiGate and 110 million compromised credentials

Colleagues, a FortiBleed campaign targeting FortiGate and other internet-facing devices has been identified.
Briefly:
- SOCRadar and SpyCloud report that since February 2026 attackers have compromised >430,000 FortiGate devices and harvested over 110 million accounts.
- They deploy FortigateSniffer (Golang) via "diagnose sniffer packet" for passive capture of authentications (~24 protocols) and subsequent hash cracking.
- The operation is multivector: mass scanning and brute-force against internet devices; a focus on SMB/IT providers; uses geo-filters and time windows.
Why it matters: perimeter compromise enables lateral movement and access to client networks.
What will you do to protect?
#cybersecurity #Fortinet #SMB #infosec

