Executive Summary
In June 2026, a significant cybersecurity incident known as 'FortiBleed' exposed credentials associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. Security researchers discovered a massive archive containing FortiGate firewall URLs, usernames, emails, and plaintext passwords from major corporations such as Chevron, Samsung, Foxconn, and Toyota. The attackers, reportedly Russian-speaking, executed over 1.1 billion credential attempts against 320,000 FortiGate VPN instances, leading to the compromise of Active Directory environments and, in some cases, the exfiltration of classified documents. Fortinet responded by emphasizing best practices like regular credential updates and enabling multi-factor authentication (MFA) to mitigate risks.
This incident underscores the critical importance of robust credential management and the implementation of MFA, especially for internet-facing systems. The scale and sophistication of the 'FortiBleed' campaign highlight the evolving tactics of cyber adversaries and the necessity for organizations to proactively secure their network infrastructures.
Why This Matters Now
The 'FortiBleed' incident highlights the urgent need for organizations to strengthen their credential management practices and implement multi-factor authentication to protect against large-scale credential compromise campaigns targeting critical network devices.
Attack Path Analysis
Attackers initiated the FortiBleed campaign by exploiting exposed Fortinet devices using previously compromised credentials, leading to unauthorized access. Once inside, they escalated privileges by leveraging administrative accounts to gain deeper control over the network. The attackers then moved laterally within the network, accessing additional systems and resources. They established command and control channels to maintain persistent access and manage compromised systems. Sensitive data was exfiltrated from the network to external servers controlled by the attackers. The campaign resulted in significant data breaches, operational disruptions, and potential exposure of classified information.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited exposed Fortinet devices using previously compromised credentials, leading to unauthorized access.
Related CVEs
CVE-2026-25815
CVSS 3.2An information disclosure vulnerability in Fortinet FortiOS through version 7.6.6 allows attackers to decrypt LDAP credentials due to weak default encryption.
Affected Products:
Fortinet FortiOS – <= 7.6.6
Exploit Status:
exploited in the wildCVE-2025-59718
CVSS 9.8An authentication bypass vulnerability in Fortinet FortiOS allows unauthenticated attackers to gain administrative access to affected devices.
Affected Products:
Fortinet FortiOS – < 7.0.15, < 7.2.6, < 7.4.2
Exploit Status:
exploited in the wildCVE-2025-59719
CVSS 9.8An authentication bypass vulnerability in Fortinet FortiOS allows unauthenticated attackers to gain administrative access to affected devices.
Affected Products:
Fortinet FortiOS – < 7.0.15, < 7.2.6, < 7.4.2
Exploit Status:
exploited in the wildCVE-2026-24858
CVSS 9.8An authentication bypass vulnerability in Fortinet FortiOS allows unauthenticated attackers to gain administrative access to affected devices.
Affected Products:
Fortinet FortiOS – < 7.0.15, < 7.2.6, < 7.4.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Brute Force
OS Credential Dumping
Application Layer Protocol
Remote Services
Account Discovery
Account Manipulation
Create Account
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Government entities face critical exposure through compromised Fortinet VPN credentials, enabling lateral movement across classified networks and potential exfiltration of sensitive data.
Financial Services
Banking institutions risk credential compromise on internet-facing Fortinet devices, threatening PCI compliance and enabling unauthorized access to financial transaction systems.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations and patient data exposure through FortiBleed credential leaks affecting 74,000 Fortinet VPN gateways globally.
Information Technology/IT
IT service providers managing client Fortinet infrastructure face cascading security incidents across multiple organizations through compromised administrative credentials and VPN access.
Sources
- CISA Urges Hardening Fortinet Devices After Reports of Credential Exposurehttps://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposureVerified
- Fortinet firewalls hit by huge password-stealing attack - around 75,000 users possibly affectedhttps://www.techradar.com/pro/security/fortinet-firewalls-hit-by-huge-password-stealing-attack-around-75-000-users-possibly-affectedVerified
- Fortinet Authentication Bypass Vulnerabilities Exploitedhttps://leargassecurity.com/2026/03/10/fortinet-authentication-bypass-vulnerabilities-exploited-for-network-breaches-cve-2025-59718-cve-2025-59719-and-cve-2026-24858/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the FortiBleed incident as it would likely have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's unauthorized access would likely have been limited to the initially compromised device, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely have been constrained, limiting their control over the network.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely have been restricted, preventing access to additional systems and resources.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely have been hindered, reducing their capacity to manage compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely have been detected and blocked, preventing sensitive information from leaving the network.
The overall impact of the attack would likely have been minimized, reducing data breaches and operational disruptions.
Impact at a Glance
Affected Business Functions
- Network Security
- Remote Access
- User Authentication
Estimated downtime: 7 days
Estimated loss: $500,000
Administrator credentials, VPN access credentials, potential exposure of sensitive corporate data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
- • Enforce phishing-resistant multifactor authentication (MFA) on all remote access and administrative accounts to prevent unauthorized access.
- • Regularly rotate and enforce strong, unique passwords for all administrative and VPN accounts to mitigate credential reuse attacks.
- • Restrict internet access to management interfaces and ensure they are only accessible from trusted internal networks.
- • Continuously monitor and analyze network traffic for anomalies to detect and respond to potential threats promptly.



