Executive Summary
In June 2026, the 'FortiBleed' campaign was uncovered, revealing that cybercriminals had compromised approximately 73,932 Fortinet FortiGate firewalls across 194 countries. The attackers, identified as Russian-speaking, executed over 1.1 billion credential attempts against FortiGate VPN instances and 2.1 billion against Microsoft SQL Server systems. They exploited weak or default credentials and intercepted SSL VPN authentication hashes, which were cracked using a 45-GPU cluster managed through Hashtopolis. This led to unauthorized access to internal Active Directory environments, affecting sectors such as government, telecommunications, financial services, healthcare, manufacturing, and critical infrastructure. Notably, a Turkish NATO defense contractor reportedly lost classified documents due to this breach.
This incident underscores the critical importance of robust credential management and the implementation of multi-factor authentication (MFA). The scale and sophistication of the FortiBleed campaign highlight the evolving tactics of threat actors and the necessity for organizations to proactively secure their network devices and monitor for unauthorized access.
Why This Matters Now
The FortiBleed campaign demonstrates the increasing sophistication and scale of cyberattacks targeting critical infrastructure. Organizations must prioritize credential security and implement multi-factor authentication to mitigate such threats.
Attack Path Analysis
Attackers initiated the campaign by conducting extensive brute-force attacks against FortiGate firewalls, leading to unauthorized access. Using the compromised credentials, they escalated privileges to access administrative functions and sensitive data. The attackers then moved laterally within the network, accessing internal systems such as Active Directory environments. They established command and control channels to maintain persistent access and exfiltrated sensitive data, including classified documents from a Turkish NATO defense contractor. The impact included widespread exposure of credentials across 194 countries, affecting government, critical infrastructure, and multinational corporations.
Kill Chain Progression
Initial Compromise
Description
Attackers conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets, leading to unauthorized access.
Related CVEs
CVE-2026-20024
CVSS 5.7A critical authentication bypass vulnerability in Fortinet FortiOS SSL-VPN allows unauthenticated attackers to gain administrative access to affected devices.
Affected Products:
Fortinet FortiOS – 7.6.x < 7.6.3, 7.4.x < 7.4.7, 7.2.x < 7.2.11, 7.0.x < 7.0.17
Exploit Status:
exploited in the wildReferences:
CVE-2026-24858
CVSS 9.8A critical vulnerability in Fortinet FortiCloud SSO allows attackers to log into FortiGate devices using unauthorized accounts.
Affected Products:
Fortinet FortiOS – 7.2.0 through 7.2.10, 7.4.0 through 7.4.7, 7.6.0 through 7.6.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
OS Credential Dumping
System Network Configuration Discovery
Network Service Scanning
Impair Defenses
Create Account
Traffic Signaling: Port Knocking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Enforce Strong Authentication
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Critical exposure through compromised FortiGate credentials enabling unauthorized access to classified systems, lateral movement within government networks, and potential espionage operations.
Telecommunications
Massive infrastructure vulnerability with 73,932 exposed FortiGate systems compromising network segmentation, encrypted traffic protection, and enabling command-and-control channel establishment across telecommunications infrastructure.
Financial Services
Severe regulatory compliance violations across PCI DSS and data protection standards through compromised network security controls, enabling credential harvesting and potential data exfiltration.
Health Care / Life Sciences
Critical HIPAA compliance breaches through exposed administrative credentials compromising patient data protection, network segmentation controls, and encrypted traffic security across healthcare infrastructures.
Sources
- FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systemshttps://www.recordedfuture.com/blog/critical-fortibleed-campaignVerified
- Fortinet firewalls hit by huge password-stealing attack - around 75,000 users possibly affectedhttps://www.techradar.com/pro/security/fortinet-firewalls-hit-by-huge-password-stealing-attack-around-75-000-users-possibly-affectedVerified
- Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the worldhttps://techcrunch.com/2026/06/17/cybercriminals-allegedly-hacked-tens-of-thousands-of-fortinet-firewalls-used-by-major-companies-all-over-the-world/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to gain unauthorized access may have been constrained by enforcing strict identity-based access controls and continuous verification mechanisms.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may have been constrained by enforcing strict segmentation and limiting access to administrative functions.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally may have been constrained by enforcing east-west traffic controls and limiting inter-workload communication.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels may have been constrained by enforcing strict monitoring and control over outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data may have been constrained by enforcing strict egress policies and monitoring outbound data flows.
The overall impact of the attack may have been constrained by limiting the attacker's ability to move laterally and exfiltrate data, thereby reducing the blast radius.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Remote Access Services
- Data Protection and Compliance
Estimated downtime: 7 days
Estimated loss: $5,000,000
Administrative and VPN credentials for approximately 73,932 FortiGate firewall URLs across 194 countries, potentially leading to unauthorized access and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Multi-Factor Authentication (MFA) on all remote and administrative access to prevent unauthorized access.
- • Regularly rotate and update credentials to mitigate the risk of credential reuse attacks.
- • Restrict or remove internet exposure for management interfaces to reduce attack surface.
- • Deploy Zero Trust Segmentation to limit lateral movement within the network.
- • Enhance monitoring and logging to detect and respond to anomalous activities promptly.



