FortiBleed: Credentials for 74,000 Fortinet Firewalls Leaked, CISA Issues Urgent Warning

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory calling on organizations running Fortinet firewalls and VPN gateways to immediately secure their devices following a large-scale credential leak referred to as “FortiBleed.” The leak, first uncovered by security researcher Volodymyr “Bob” Diachenko, involves a server containing what appear to be valid credentials — including usernames, email addresses, and plaintext passwords — for approximately 73,932 Fortinet devices across 21,632 unique domains and 194 countries. Threat intelligence firm Hudson Rock, which independently analyzed the dataset, described it as one of the largest known collections of compromised Fortinet credentials ever assembled, and has made a free lookup tool available at hudsonrock.com/fortinet.

The affected organizations span an unusually broad range of sectors. Among the named entities identified in the dataset are Samsung, Mercedes-Benz, Foxconn, Chevron, Comcast, AT&T, and Toyota, alongside numerous government agencies and critical infrastructure operators in telecommunications, healthcare, financial services, and manufacturing. The countries with the highest concentrations of affected devices include India, the United States, Taiwan, Mexico, and Turkey. Notably, the dataset also includes information such as each organization’s industry, revenue, and employee count — details that Diachenko assessed were likely compiled to support targeted follow-on attacks.

Diachenko has attributed the operation to a Russian-speaking threat group that reportedly conducted roughly 1.16 billion credential attempts against more than 320,000 FortiGate targets in order to intercept SSL VPN authentication hashes. Independent cybersecurity researcher Kevin Beaumont confirmed that a sample of the leaked credentials appeared valid and that nearly all affected devices remained online at the time of his analysis. The precise method of data collection remains under investigation — it is not yet clear whether the credentials were obtained by exploiting known Fortinet vulnerabilities, a previously undisclosed flaw, or another technique.

CISA’s advisory recommends that affected organizations terminate all active SSL VPN and administrative sessions, reset VPN and administrative passwords across the board, enable phishing-resistant multi-factor authentication, and review logs for evidence of unauthorized access or lateral movement within their networks. The agency also advises storing administrator credentials using the PBKDF2 hashing algorithm and restricting management interfaces from being accessible over the public internet. This incident arrives amid a broader pattern of Fortinet exploitation: CISA currently tracks 26 Fortinet vulnerabilities that have been exploited in the wild, 13 of which have been leveraged in ransomware attacks.

Read the original report →