FortiBleed Campaign Compromises Fortinet Devices, Exposing Siemens Credentials
Alert - AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices This Alert is intended for IT professionals and managers.
Key points
- Widespread cyber espionage campaign 'FortiBleed' targeted Fortinet devices.
- Siemens identified as one of the high-profile victims.
- Attackers gained access by exploiting exposed Fortinet firewalls and VPN gateways.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Jun 17, 2026
- Updated
- Jul 22, 2026
- Confidence
- Medium
- Evidence
- 2 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch process controls, misconfiguration and accidental disclosure paths.
- Source type: possible insider or internal misuse
Business impact
- Impact area
- Confidentiality
- Likely asset
- User or customer data, Server or cloud data store
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
Alert - AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. On June 17, 2026, the Canadian Centre for Cyber Security (Cyber Centre) became aware of open-source reporting Footnote 1 Footnote 2 Footnote 3 Footnote 4 describing a widespread malicious campaign, known as “FortiBleed,” involving exposed credentials affecting Fortinet firewalls and VPN gateways. Exploitation of these credentials could allow malicious actors to gain remote access to affected devices and connected networks, as well as modify various system settings, including critical security controls. The Cyber Centre strongly recommends that organizations : Inventory all accounts on Fortinet devices, identify unauthorized or suspicious accounts (e.g., forticloud-sync , forticloud-tech ) and disable/remove suspected or unneeded accounts. Restrict access to management interfaces to trusted networks and hosts only. Terminate all active SSL VPN and administrative sessions. Reset passwords for all Fortinet VPN and administrative accounts. Enforce Multi-Factor Authentication (MFA) across all external gateways and admin interfaces. Ensure all Fortinet devices are running the latest firmware. Specifically, check for patches related to CVE-2024-55591 (obtain high privileges) Footnote 5 and, CVE-2025-59718 Footnote 6 and CVE-2025-59719 Footnote 7 (authentication bypass) Footnote 8 . In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions with an emphasis on the following topics Footnote 9 . Consolidate, monitor and defend Internet gateways Patch operating systems and applications Enforce the management of administrative privileges Harden operating systems and applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal , or email contact@cyber.gc.ca . FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure Fortinet firewalls and VPN gateways serve as the primary defensive perimeter for countless organizations worldwide. However, a massive new cyber espionage campaign has silently compromised these highly trusted devices on an unprecedented global scale. Originally discovered by security researcher Volodymyr “Bob” Diachenko , with further analysis from Hudson Rock and cybersecurity expert Kevin Beaumont , this dataset exposes a massive, automated operation. Threat actors successfully targeted 73,932 unique firewall URLs across 194 countries, resulting in 21,632 unique affected domains . Astonishingly, as Beaumont highlighted, this represents roughly 50% of all Fortinet firewall devices currently facing the internet . Attacker Methodology & Unprecedented Scale According to Diachenko’s investigative report, this campaign is orchestrated by a multi-operator, Russian-speaking cybercriminal group. The operation’s footprint is staggering: the attackers executed an estimated 1.16 billion credential attempts against over 320,000 FortiGate targets, alongside an additional 2.1 billion brute-force attempts directed at over 160,000 MSSQL servers. The group’s methodology goes beyond simple credential reuse. They actively intercept SSL VPN authentication hashes and crack them using a massive, dedicated 45-GPU cluster managed via Hashtopolis. Once the perimeter is breached, the operators systematically pivot directly into internal Active Directory environments to establish deep network persistence. This aggressive methodology has led to severe, real-world consequences. Diachenko’s research confirmed full network compromises at multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey. Most alarmingly, this includes a Turkish NATO defense contractor from which classified defense documents were successfully exfiltrated by the group. Beaumont notes a sharp contrast between this incident and the prior “Belsen Group” leak of 15,000 devices from a 2022 zero-day. This dataset represents active, recent compromises—with many of the affected devices running recent patches. Furthermore, Beaumont observed that the formatting of the leaked data, which explicitly categorizes victims by company type, revenue, and country, is a hallmark of eCrime syndicates packaging initial access for sale on the dark web. As Beaumont explains in his blog , the attackers likely exploited older credential hashing mechanisms to pull this off. While Fortinet hardened admin credential storage in early 2025 by moving to PBKDF2, this protection only applied if administrators actively logged in after applying the firmware updates. Consequently, many devices continued storing credentials using the older, more vulnerable SHA-256 with Salt format, making them highly susceptible to offline brute-forcing once the configuration files were extracted. The scale of this breach touches nearly every sector of the global economy, sparing no industry. The threat actors have built a verified database of working credentials for some of the largest enterprises on the planet. Among the victims discovered in this dataset are massive multinational corporations, including: …and thousands of others, including major government entities and critical infrastructure providers. When examining the attacker infrastructure, it becomes clear how systematic and devastating this campaign is. The attackers maintained highly organized logs of successful breaches. A particularly alarming detail from this dataset is the high volume of extremely complex passwords that were successfully compromised. IT departments frequently lean on rigid password complexity rules as their main line of defense. However, complexity is completely neutralized when passwords are recovered in plaintext. Whether threat actors leverage specific device exploits that expose plaintext credentials, or utilize databases previously harvested by Infostealers, a 20-character complex string is just as vulnerable as a simple one. If the attackers are recycling known plaintext credentials to bypass perimeters, complexity policies offer no protection. To secure your network against this specific vector, we strongly recommend the following immediate actions: Remove Internet Exposure: Immediately ensure the FortiOS Management Interface is not exposed to the public internet unless absolutely necessary. Force Credential Rotation & Upgrade Hashing: Upgrade to the latest FortiOS release and have all admins log back in to force the system to re-hash passwords using the more secure PBKDF2 standard. Enforce Strict MFA: Ensure Multi-Factor Authentication is universally applied to all external gateways and admin interfaces, effectively neutralizing the threat of stolen plaintext passwords. 🚨 Free Look-Up Tool for Affected Organizations
When was this signal reported?
Shadow Tier lists Jun 17, 2026 as the signal date.
Which organization is connected to this signal?
Siemens is the organization connected to this public signal.
Explore SiemensWhich attack pattern is relevant?
This signal is connected to vulnerability-exploitation intelligence based on its reported incident context.
Explore vulnerability-exploitation intelligenceWhich impact area is relevant?
This signal is connected to data exposure and breach intelligence based on its reported consequences.
Explore data exposure and breach intelligence