CISA Issues Alert on Active Exploitation Following FortiBleed Leak

0
31

Key Takeaways

  • CISA issued an emergency alert on June 18, 2026 after confirming that roughly 74 000 Fortinet firewall and VPN gateway credentials were leaked in a campaign dubbed FortiBleed.
  • Attackers are actively using the exposed credentials to compromise internet‑accessible Fortinet devices across government and private‑sector organizations worldwide.
  • The leaked data originated from exported device configuration files, giving threat actors access to usernames, email addresses, plaintext passwords, and additional business‑intelligence fields (industry, revenue, employee count, country) that suggest the information was assembled for sale or coordinated use.
  • Hudson Rock’s analysis shows the dataset covers about 50 % of all Fortinet devices facing the internet, spanning 194 countries and 21 632 unique domains, including major corporations such as Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, Chevron, and numerous government agencies.
  • Investigators discovered an open directory containing the attackers’ tooling, indicating a Russian‑speaking multi‑operator threat group that performed roughly 1.16 billion credential attempts against FortiGate targets and 2.1 billion attempts against Microsoft SQL Server systems.
  • CISA’s mitigations include terminating active SSL VPN and admin sessions, resetting all VPN and admin passwords, enforcing phishing‑resistant MFA on admin interfaces, reviewing logs for unauthorized activity, upgrading to the latest FortiOS release, triggering re‑hashing of stored credentials to PBKDF2, and removing the FortiOS management interface from public exposure unless absolutely necessary.
  • Organizations should treat any unexpected successful admin login as a sign of compromise and consider device replacement if backdoor accounts or configuration changes are suspected.

Overview of the FortiBleed Incident

On June 18, 2026 the Cybersecurity and Infrastructure Security Agency (CISA) released an emergency alert after threat intelligence revealed that credentials for approximately 74 000 Fortinet firewalls and VPN gateways had been exposed. The leak, subsequently named FortiBleed, involves usernames, email addresses, and plaintext passwords that threat actors are already using to target internet‑accessible Fortinet devices across the globe. CISA’s alert emphasized that the activity is ongoing and affects both government and private‑sector organizations.

Discovery of the Leaked Dataset

Security researcher Bob Diachenko first noticed an openly accessible server on the internet containing what appeared to be valid Fortinet VPN credentials. He shared his findings on LinkedIn, prompting independent expert Kevin Beaumont to obtain the dataset and collaborate with Hudson Rock for verification. Beaumont confirmed the data’s legitimacy, estimating it covers around 75 000 devices, most of which remain online and are indeed Fortinet appliances.

Nature and Source of the Exposed Data

Unlike a simple credential scrape, the leaked information appears to have been derived from exported device configuration files. Such exports contain details unavailable from passive traffic interception, indicating that the attackers had achieved some level of device access at some point—whether through a known Fortinet CVE, a zero‑day, or another means. The data includes not only login credentials but also business‑intelligence fields (industry, revenue, employee count, country) formatted in a manner typical of criminal markets selling initial‑access information.

Scale and Geographic Reach

Hudson Rock’s analysis revealed that the 73 932 unique firewall URLs in the dataset span 194 countries and 21 632 unique domains. Prominent names identified include Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, Chevron, and Fortinet itself, alongside numerous government agencies and critical‑infrastructure operators. Based on Shodan polling, the dataset represents roughly half of all Fortinet firewall devices currently exposed to the public internet.

Attacker Infrastructure and Activity

Diachenko’s investigation uncovered an open directory left by the attackers that housed their own tooling, scripts, connection strings, logs, and analytics. This evidence points to a Russian‑speaking multi‑operator threat group that conducted approximately 1.16 billion credential‑guessing attempts against 320 777 FortiGate targets and 2.1 billion attempts against 163 650 Microsoft SQL Server systems. The group employed a 45‑GPU cluster managed through Hashtopolis to crack SSL‑VPN authentication hashes, enabling them to obtain plaintext passwords for lateral movement and network takeover.

Impact on Victim Organizations

Multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were reported as fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly stolen. Because the attackers could log in remotely via SSL VPN, gain administrative control of the firewall, alter security settings, and create persistent backdoor admin accounts, the potential for data exfiltration, ransomware deployment, or further intrusion is significant.

Technical Details on Credential Storage

Beaumont noted that Fortinet began storing credentials using PBKDF2 in early‑2025 firmware updates, but only for devices where administrators had logged in after applying the update. Many devices in the leaked dataset still relied on SHA‑256 with salt, a hash that remains susceptible to brute‑force attacks when the configuration file is stolen. This discrepancy explains why the attackers were able to recover plaintext passwords at scale despite newer security measures on some devices.

Mitigation Guidance from CISA

CISA’s alert provides a set of non‑negotiable actions for any organization running Fortinet equipment:

  1. Terminate all active SSL VPN and administrative sessions immediately.
  2. Reset every VPN and administrative password.
  3. Enable phishing‑resistant multi‑factor authentication on all admin interfaces.
  4. Review logs for unauthorized access or lateral movement.
  5. Upgrade to the latest FortiOS release and have each admin log back in to trigger re‑hashing of stored credentials to PBKDF2.
  6. Remove the FortiOS management interface from public internet access unless absolutely necessary, and delete any unauthorized accounts.
  7. Treat unexpected successful admin logins as indicative of compromise; consider device replacement if backdoor accounts or configuration changes are suspected.

Tools for Verification

Hudson Rock has made available a free lookup tool at hudsonrock.com/fortinet where organizations can check whether their domain appears in the leaked dataset. This resource allows rapid assessment of exposure and prioritization of remediation efforts.

Conclusion

The FortiBleed incident underscores the critical risk posed by exposed device configuration files and the importance of securing management interfaces, enforcing strong authentication, and maintaining up‑to‑date firmware. By following CISA’s directives and leveraging available verification tools, organizations can mitigate the immediate threat and reduce the likelihood of future compromise stemming from similar credential leaks.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here