started · updated
FortiBleed credential‑spraying campaign compromises ~75,000 FortiGate firewalls globally
A coordinated credential‑spraying operation dubbed "FortiBleed" has targeted Fortinet FortiGate SSL VPN devices worldwide. Researchers observed roughly 1.16 billion login attempts across 320,000 endpoints, using a custom tool that sprayed 3,639 credential pairs in billions of combinations. The campaign is estimated to have affected about 75,000 firewalls in 207 countries, with sectors such as IT services, telecommunications, financial services and government among the most exposed.
In Germany, the attack forced local authorities in Oranienburg to shut down municipal systems as a precaution, briefly limiting public services. The operation also reportedly breached a Turkish defence contractor with NATO links, and compromised organizations in Japan, Taiwan, Vietnam, Iraq and other regions. Analysts warn that exposed firewalls often indicate deeper compromises, including credential theft from network traffic and lateral movement into Active Directory.
Security experts recommend removing public exposure of management interfaces, enforcing strong authentication, rotating all credentials, applying firmware updates, and invalidating active VPN sessions to mitigate the threat.