FortiBleed Campaign Harvests 110M+ Credentials, Fuels Ransomware Operations
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A large-scale credential-harvesting campaign called 'FortiBleed' has been uncovered, targeting over 430,000 internet-facing FortiGate firewalls by exploiting CVE-2026-35616 (CVSS 9.1) in FortiClient EMS. Attributed to a Russian-speaking initial access broker, the campaign deployed a custom Golang packet sniffer ('FortigateSniffer') on ~12,000 devices to passively intercept authentication traffic across 24 protocols, amassing over 110 million credentials. The operation is directly linked to INC Ransom and Lynx ransomware-as-a-service groups, with at least 12 confirmed ransomware deployments. Immediate mitigations include upgrading FortiClient EMS to 7.4.7+, rotating all credentials, auditing for the 'adminin' backdoor account, restricting port 8013, and enabling MFA on FortiGate admin interfaces.