---
title: "FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems"
url: https://daily.dev/posts/fortibleed-campaign-exposing-credentials-for-73-932-fortigate-systems-yp7bznbqe
source_url: https://www.recordedfuture.com/blog/critical-fortibleed-campaign
type: article
source: "Recorded Future Blog"
published: 2026-06-19T14:45:36.546Z
updated: 2026-06-19T14:58:56.628Z
tags: ["security", "active-directory", "fortinet"]
reading_time: 5
upvotes: 2
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems

**[Recorded Future Blog](https://daily.dev/sources/recorded-future-blog)** · 5 min read · 2 upvotes · 0 comments

## Summary

A dataset dubbed 'FortiBleed' containing valid administrative and SSL VPN credentials for 73,932 FortiGate firewall URLs across 194 countries has been attributed to a Russian-speaking threat group. Researchers including Kevin Beaumont and Hudson Rock independently verified portions of the dataset as authentic. Attackers conducted over 1.16 billion credential attempts, intercepted SSL VPN authentication hashes, cracked them offline using a 45-GPU Hashtopolis cluster, and then accessed internal Active Directory environments. Affected sectors include government, telecom, financial services, healthcare, and critical infrastructure, with a confirmed NATO defense contractor among victims. Recorded Future's Insikt Group identified attacker infrastructure hosting sniffer logs, hash-cracking scripts, AD enumeration tools, and log-clearing markers. Organizations running Fortinet devices are urged to immediately rotate credentials, enforce MFA, restrict management interface exposure, and hunt for downstream compromise.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.recordedfuture.com/blog/critical-fortibleed-campaign>

## Similar posts on daily.dev

- [FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.](https://daily.dev/posts/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices--gws8xvpp9) · BleepingComputer · 1 upvotes · 0 comments
- ['FortiBleed': 75,000 Fortinet firewalls' logins exposed](https://daily.dev/posts/fortibleed-75-000-fortinet-firewalls-logins-exposed-ttnarklo4) · The Next Web · 0 upvotes · 0 comments
- [FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation](https://daily.dev/posts/fortibleed-targeted-fortigate-firewalls-in-110-million-credential-harvesting-operation-21lcgrxcc) · Security Boulevard · 0 upvotes · 0 comments
- [FortiBleed Campaign Harvests 110M\+ Credentials, Fuels Ransomware Operations](https://daily.dev/posts/fortibleed-campaign-harvests-110m-credentials-fuels-ransomware-operations-jiqarmttq) · Orca Security Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#active-directory](https://daily.dev/tags/active-directory), [#fortinet](https://daily.dev/tags/fortinet)

[View this post on daily.dev](https://daily.dev/posts/fortibleed-campaign-exposing-credentials-for-73-932-fortigate-systems-yp7bznbqe)
