VMTech
Discuss a project

FortiBleed: Attack on FortiGate and 110 million compromised credentials

FortiBleed: Attack on FortiGate and 110 million compromised credentials

Colleagues, a FortiBleed campaign targeting FortiGate and other internet-facing devices has been identified.

Briefly:
- SOCRadar and SpyCloud report that since February 2026 attackers have compromised >430,000 FortiGate devices and harvested over 110 million accounts.
- They deploy FortigateSniffer (Golang) via "diagnose sniffer packet" for passive capture of authentications (~24 protocols) and subsequent hash cracking.
- The operation is multivector: mass scanning and brute-force against internet devices; a focus on SMB/IT providers; uses geo-filters and time windows.

Why it matters: perimeter compromise enables lateral movement and access to client networks.

What will you do to protect?

#cybersecurity #Fortinet #SMB #infosec

Open analytics
On the site 1 views
min read 1 28.06.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

FortiBleed: Attack on FortiGate and 110 million compromised credentials

Open the post on Instagram ↗