Skip to main content
Back to overview
Medium

FortiBleed Campaign Compromises Fortinet Devices, Exposing PwC Credentials

PwC was identified as one of the global enterprises impacted by the 'FortiBleed' cyber espionage campaign.

Key points

  • Widespread cyber espionage campaign 'FortiBleed' targeted Fortinet devices.
  • PwC identified as one of the high-profile victims.
  • Attackers gained access by exploiting exposed Fortinet firewalls and VPN gateways.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Potential data exposure

Confidentiality

Published
Jun 17, 2026
Updated
Jun 26, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

PwcData DisclosureFortiBleed Campaign Compromises Fortinet DevicesExposing PwC Credentials PwCFortiBleedFortinetVPNWidespreadPwCAttackers

Quick context

Questions about this signal

What happened in this signal?

PwC was identified as one of the global enterprises impacted by the 'FortiBleed' cyber espionage campaign. This campaign involved the compromise of Fortinet firewalls and VPN gateways, where attackers exploited exposed instances to extract and brute-force credentials. The Canadian Centre for Cyber Security became aware of the widespread malicious activity on June 17, 2026.

When was this signal reported?

Shadow Tier lists Jun 17, 2026 as the signal date.

Which organization is connected to this signal?

Pwc is the organization connected to this public signal.

Explore Pwc