XOOMAR
Enterprise network devices protected by a digital shield after a major credential leak
CybersecurityJune 19, 2026· 6 min read· By XOOMAR Insights Team

74,000 Fortinet Logins Spill in FortiBleed Data Leak

Share
Updated on June 19, 2026

73,932 Fortinet firewall URLs were listed with usernames, email addresses, and plaintext passwords in the FortiBleed leak, prompting CISA to urge customers to lock down exposed firewalls and VPN gateways immediately.

XOOMAR Intelligence

Analyst Take

58/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness97Source Trust88Factual Grounding96Signal Cluster20

The warning follows reports that attackers used compromised credentials to target internet-accessible Fortinet devices across government and private-sector organizations worldwide, according to BleepingComputer.

CISA says FortiBleed exposed credentials tied to about 74,000 Fortinet devices

CISA said the activity, referred to as FortiBleed, involves leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways.

“CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials,” the agency said.

The agency’s alert focuses on FortiGate appliances and associated SSL VPN gateways, the systems many organizations use to control remote access and sit at the network edge. That placement makes leaked credentials especially dangerous. A valid login can put an attacker at the front door of an internal network, not just inside a single application.

CISA’s advice is blunt: terminate all active SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant MFA, review logs, restrict management interfaces from the public internet, and remove unauthorized accounts.

The agency also told customers to confirm use of Password-Based Key Derivation Function 2 (PBKDF2) for administrator credential storage and remove weaker legacy hashes under Fortinet’s guidance.

21,632 domains and 194 countries appear in the FortiBleed dataset

Security researcher Volodymyr “Bob” Diachenko found a server containing what appeared to be valid Fortinet VPN credentials. The exposed data included usernames, email addresses, and plaintext passwords for 73,932 firewall URLs worldwide, BleepingComputer reported.

The dataset also contained each organization’s industry, revenue, and employee count. Diachenko said that information appeared to be compiled to help plan future attacks.

Threat intelligence firm Hudson Rock analyzed the data and described it as one of the largest known collections of compromised Fortinet credentials. It said the leak spans 21,632 unique domains and 194 countries.

Named organizations represented in the dataset include Samsung, Mercedes-Benz, Foxconn, Chevron, Comcast, AT&T, and Toyota, along with government agencies and critical infrastructure operators across telecommunications, healthcare, financial services, and manufacturing.

The highest number of affected devices were in India, the United States, Taiwan, Mexico, Turkey, Thailand, Colombia, Malaysia, Chile, and the United Arab Emirates.


FortiBleed turns valid logins into a network-edge problem

The FortiBleed risk is not framed as a single confirmed zero-day. Integrity360’s advisory said the campaign is “not a single CVE or confirmed zero-day flaw,” but instead an active credential exposure and exploitation campaign using reused and potentially exposed credentials at scale.

That distinction matters. Patching alone won’t fix an active password that still works.

Risk area Why it matters in FortiBleed
Valid credentials Attackers may log in without triggering exploit-based detections.
Internet-facing VPNs Remote access systems are reachable from outside the organization.
Public management interfaces Exposed admin panels increase the attack surface.
Weak log visibility CISA specifically told customers to review firewall, VPN, authentication, and domain controller logs.

Diachenko also said the operation was conducted by a Russian-speaking threat group that allegedly carried out approximately 1.16 billion credential attempts against more than 320,000 FortiGate targets to intercept SSL VPN authentication hashes.

Cybersecurity expert Kevin Beaumont said he independently confirmed the authenticity of some credentials and noted that most affected devices remain online.

“The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data,” Beaumont said, according to BleepingComputer.

The source of the configuration data remains unknown. BleepingComputer reported that it is unclear whether the data was stolen through exploitation of previously disclosed Fortinet vulnerabilities, a newly discovered flaw, or another method.

Fortinet users should rotate credentials, kill sessions, and review logs now

CISA’s response steps read like an emergency credential reset playbook, not a routine maintenance notice.

Organizations with impacted Fortinet systems should immediately:

  • Terminate sessions: End all active SSL VPN and administrative sessions.
  • Reset credentials: Change all Fortinet VPN and administrative passwords, especially on internet-facing systems.
  • Enforce MFA: Require phishing-resistant MFA on remote access and administrative accounts.
  • Review logs: Check firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes.
  • Lock down interfaces: Keep firewall administration off the public internet and restrict Fortinet management interfaces to trusted internal networks.
  • Remove accounts: Disable unauthorized or unnecessary accounts.
  • Check hashing: Confirm administrator credentials are stored with PBKDF2 and remove weaker legacy hashes.

Hudson Rock has also created a free FortiBleed lookup tool to help organizations check whether they are affected.

For security teams, the hard part is proving whether valid credentials were already used. CISA’s recommended log review points directly at that problem. Teams need to look for unusual VPN logins, new admin users, configuration changes, unexpected access patterns, and signs of lateral movement.

Log retention and alerting discipline now matter. For separate operational context, XOOMAR has covered how storage and detection decisions can strain teams in Budget Bomb Hides Inside SIEM Data Ingestion Costs and how lean teams compare options in Best SIEM Tools That Won't Drown Lean Security Teams.

CISA tracks 26 exploited Fortinet flaws, but FortiBleed’s source is still unresolved

BleepingComputer reported that CISA tracks 26 Fortinet security flaws exploited in the wild in recent years, including 13 abused in ransomware attacks. Separately, threat intelligence company Defused reported that several critical vulnerabilities in Fortinet’s FortiSandbox cyber threat detection platform are now exploited in attacks.

That history raises the stakes, but it does not answer the central FortiBleed question: where did this credential and configuration data come from?

The next useful disclosures would be concrete indicators of compromise, affected product details, guidance from Fortinet, and clearer evidence about how many leaked credentials still work. Until then, the practical path is narrower and urgent: rotate credentials, terminate sessions, lock down management access, and hunt through logs before attackers do it for you.

Impact Analysis

  • Leaked plaintext credentials could give attackers direct access to Fortinet firewalls and VPN gateways.
  • CISA’s warning affects both government and private-sector organizations using internet-exposed Fortinet devices.
  • Immediate password resets, MFA, log reviews, and restricted management access can reduce the risk of network compromise.

FortiBleed Exposure Indicators

Fortinet firewall URLs
count73,932
Domains
count21,632
Countries
count194
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Snowy water utility shielded from cyber intrusions with dark code overlays and security locks.Cybersecurity

Iran Shadow Looms Over Minnesota Water Cyberattacks

A leaked memo links 30-plus Minnesota water utility intrusions to Iran-affiliated hackers, raising alarms over civilian infrastructure.

Aug 2, 20268 min
Minnesota water utility facility under cyberattack with digital shields, locks, and dark data network visuals.Cybersecurity

30 Minnesota Water Systems Rattled by Cyberattacks

More than 30 Minnesota water systems were hit in two days, exposing weak utility defenses as officials warn about Iranian hackers.

Aug 1, 202611 min
Dark cybersecurity scene with phone tracking, malware, shields and encrypted data networks.Cybersecurity

Iran Turns US Military Phones Into Tracking Beacons

Iran-linked tracking of US military phones shows commercial data is now a battlefield risk, with macOS malware and vendor breaches piling on.

Jul 17, 20267 min
Dark server room under cyberattack with glowing shields, locks, and code matrix symbolizing data protection.Cybersecurity

Hackers Exploit SharePoint Server Flaws, CISA Warns

CISA says three SharePoint flaws are under attack, with two critical bugs waiting to widen the blast radius for unpatched servers.

Jul 15, 20267 min
Enterprise servers under cyberattack protected by glowing shields and urgent patching visuals.Cybersecurity

Exploited SharePoint Vulnerabilities Trigger 3-Day Race

CISA says three exploited SharePoint flaws are under attack, with agencies facing a 3-day patch deadline for CVE-2026-56164.

Jul 15, 20265 min
Detailed map showing COVID-19 global cases with data visualization by country.Global Trends

Salmonella Jalapeño Outbreak Sends 36 to Hospital

At least 345 people in 27 states have been sickened, with 36 hospitalized, in a Salmonella outbreak traced to jalapeños served at major restaurant chains and di

Aug 6, 20264 min
Portrait of a young woman holding a world map against a vivid blue background.Global Trends

Senators Hold Fauci in Contempt as COVID Probe Collapses

A Senate committee voted to hold Dr. Anthony Fauci in contempt of Congress, a partisan act his lawyer denounced as political theater that blocks real pandemic a

Aug 6, 20267 min
Candlestick chart showing a downward trend in the stock market analysis.Trading

Apollo Wins $5.7B EasyJet Takeover With Founder Backing

US private equity giant Apollo Global Management will acquire EasyJet for £5.7 billion (£7.15 per share), backed by the airline's founder, taking the iconic low

Aug 6, 20265 min
Detailed political map showing Europe and Asia with countries and capitals.Global Trends

Ukraine's 'Deep Strike' Strategy Cripples Russia's Oil Revenue

Ukraine has shifted to a strategy of 'deep strikes', using drones to attack oil refineries and military hubs inside Russia, aiming to cripple the economic engin

Aug 6, 20267 min
A detailed financial trading chart showing a candlestick pattern with market trends.Trading

Dollar Flips Its Script As Silver Rally Collapses

Silver's rally is collapsing under pressure from a rebounding U.S. Dollar and shifting Fed rate expectations ahead of key employment data.

Aug 6, 20268 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.