A dataset dubbed 'FortiBleed' containing valid administrative and SSL VPN credentials for 73,932 FortiGate firewall URLs across 194 countries has been attributed to a Russian-speaking threat group. Researchers including Kevin Beaumont and Hudson Rock independently verified portions of the dataset as authentic. Attackers conducted over 1.16 billion credential attempts, intercepted SSL VPN authentication hashes, cracked them offline using a 45-GPU Hashtopolis cluster, and then accessed internal Active Directory environments. Affected sectors include government, telecom, financial services, healthcare, and critical infrastructure, with a confirmed NATO defense contractor among victims. Recorded Future's Insikt Group identified attacker infrastructure hosting sniffer logs, hash-cracking scripts, AD enumeration tools, and log-clearing markers. Organizations running Fortinet devices are urged to immediately rotate credentials, enforce MFA, restrict management interface exposure, and hunt for downstream compromise.