Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

86576

FortiBleed Shows How Compromised Security Appliances Can Become Credential Collection Points

Overview

The FortiBleed campaign highlights one of the most sensitive risks in enterprise infrastructure: compromised security appliances being used to collect credentials and enable access to internal environments.

Public reporting describes FortiBleed as a large-scale credential collection campaign mainly targeting internet-facing Fortinet FortiGate firewalls and VPN environments. Initial reporting identified tens of thousands of confirmed Fortinet/FortiGate credentials, while SOCRadar’s deeper analysis describes a broader campaign involving more than 430,000 targeted FortiGate devices.

Fortinet has stated that the campaign does not appear to involve a new zero-day vulnerability. Instead, it is linked to older credentials, exposed management surfaces, weak configurations, and reused access data.

What Happened

FortiBleed came to light after exposed attacker infrastructure was discovered in connection with a credential collection campaign. Public reports indicate that the exposed data included Fortinet/FortiGate device URLs, usernames, email addresses, and passwords, some of which were confirmed as valid.

SOCRadar’s broader analysis describes the activity as likely connected to a financially motivated initial access broker. This matters because access collected in this way is often later sold or reused by ransomware operators, data theft groups, or other adversaries.

The campaign is not limited only to Fortinet environments. Some reporting also describes reconnaissance against other services and devices, indicating a broader pattern of mass access collection against perimeter infrastructure.

How the Attack Works

FortiBleed should not be understood as a single intrusion into one organization. It is better described as an industrialized operation for collecting, validating, and reusing access.

A typical model includes several stages:

  • discovering internet-facing FortiGate devices and VPN portals;
  • using leaked, old, or reused credentials;
  • validating whether the credentials still work;
  • collecting configuration data, hashes, passwords, or session information;
  • using access to move further into internal environments;
  • selling or reusing access through other threat actors.

Deeper technical analysis also describes tooling for traffic interception, credential parsing, and hash cracking. This indicates that the campaign was not focused only on one-time access, but on building a large operational dataset of working credentials.

Why This Matters

FortiGate devices often sit at the boundary between an organization and the internet. They manage VPN access, traffic filtering, connection policies, and communication between external and internal environments.

When such a device is compromised, or when valid stolen credentials are used against it, the risk becomes significant:

  • attackers may gain entry into the internal network;
  • VPN access may appear legitimate;
  • additional credentials may be collected;
  • lateral movement may become possible;
  • access may be sold to other groups;
  • response may be delayed if activity resembles normal administrative or VPN use.

This makes the case especially relevant for organizations that rely on perimeter devices but lack sufficient visibility into their activity.

Potential Impact

The impact depends on whether an organization appears in the exposed data, whether passwords were still valid at the time of exposure, and whether the access was used afterward.

Possible consequences include:

  • compromised VPN accounts;
  • access to administrative interfaces;
  • collection of internal information;
  • abuse of Active Directory identities;
  • access to shared file resources;
  • preparation for ransomware deployment;
  • broader data exposure;
  • urgent credential rotation and log review requirements.

Changing only the FortiGate administrator password may not be enough. If other credentials were captured or used through the device, organizations should also review related VPN, RADIUS, LDAP, Active Directory, and administrative accounts.

Recommended Actions

Organizations using Fortinet FortiGate or Fortinet VPN should treat FortiBleed as a trigger for immediate exposure, access, and log review.

Priority actions include:

  • check whether domains, IP addresses, or devices appear in FortiBleed exposure checks;
  • rotate FortiGate administrator and VPN credentials;
  • rotate related RADIUS, LDAP, and Active Directory credentials where risk is suspected;
  • enforce or review multi-factor authentication;
  • remove management interfaces from direct internet exposure;
  • restrict administrative access to trusted IP addresses or VPN-only access;
  • review SSH, SSL VPN, and administrator logs;
  • look for unusual logins, mass access attempts, and access from unexpected countries;
  • inspect configuration changes;
  • update to supported FortiOS versions;
  • review password reuse and credential storage practices.

DIAMATIX Perspective

FortiBleed shows why security infrastructure should not be treated as automatically trusted simply because it is a security device.

Perimeter devices are strong control points, but they are also high-value risk points. When a VPN portal, firewall, or management interface remains exposed, outdated, or protected by weak or reused credentials, it can become an entry point for deeper compromise.

The main lesson is not only to rotate passwords. The important question is whether the access was already used, what was reachable through it, and whether there are signs of lateral movement.

Protection should combine:

  • vulnerability management;
  • VPN and firewall activity monitoring;
  • privileged access control;
  • log analysis;
  • credential rotation and validation;
  • compromise assessment;
  • incident response when unauthorized access is suspected.

CISO Analysis

From a CISO perspective, FortiBleed is a perimeter, identity, and operational resilience risk.

Key questions include:

  • Which FortiGate devices are internet-facing?
  • Are any management interfaces publicly exposed unnecessarily?
  • Are old or reused passwords still active?
  • Are all VPN accounts protected with multi-factor authentication?
  • Can we see unusual VPN and SSH logins?
  • Are there signs of configuration changes?
  • If a password was exposed, do we know where else it was used?
  • Can the SOC distinguish normal VPN access from attacker access using valid credentials?

This type of campaign shows that valid credentials are often more dangerous than an exploit. They allow attackers to appear as legitimate users or administrators while preparing follow-on activity.

What This Means for Your Environment

  • This type of attack relies on valid or reused credentials, internet-facing perimeter devices, and limited visibility into VPN and administrative activity.
  • Detection depends on monitoring firewall, VPN, SSH, RADIUS, LDAP, and Active Directory activity, as well as unusual login behavior and configuration changes.
  • Response requires credential rotation, management interface restriction, log review, lateral movement checks, and continued monitoring after initial containment.

Do you know whether your FortiGate devices appeared in similar datasets?

Can you detect unauthorized VPN access if the attacker uses valid credentials?

See how credential theft campaigns are analyzed and handled in real operational environments.

Contact DIAMATIX
Trusted · Innovative · Vigilant


Sources

  • SOCRadar. Dismantling FortiBleed technical report.
  • Fortinet. Public response to the FortiBleed campaign.
  • BleepingComputer. FortiBleed leak reporting.
  • Recorded Future. FortiBleed campaign analysis.

This article is based on publicly available technical information and analysis as of June 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.