started · updated
FortiBleed cyber‑attack compromises tens of thousands of Fortinet firewalls worldwide
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency alert about a large‑scale campaign dubbed “FortiBleed,” in which Russian‑speaking threat actors have exploited leaked credentials to gain access to internet‑facing Fortinet FortiGate firewalls and VPN gateways. Estimates of compromised devices range from about 74,000 to 86,600 across more than 80,000 IP‑exposed units. Approximately 35 % of compromised logins are generic admin accounts, 28 % are built‑in system accounts, and the remaining 37 % are organization‑specific credentials harvested from prior breaches.
Telecom, government and education sectors are the most affected, with the highest concentrations of exposed devices reported in India, the United States, Mexico, Colombia, Thailand and Turkey. Attackers first scan for vulnerable endpoints, then use brute‑force and credential‑stuffing techniques to obtain valid logins, subsequently monitoring traffic to harvest additional credentials and expand their foothold. CISA recommends immediately terminating all active SSL‑VPN and administrative sessions, resetting passwords, enforcing multi‑factor authentication, and updating firmware to versions that employ PBKDF2‑based password hashing.
Fortinet officials note that many organizations still store administrator passwords using legacy SHA‑256 hashes, leaving them vulnerable even after firmware upgrades. The breach underscores a global failure to rename default accounts and rotate credentials, highlighting the need for stronger credential hygiene across the worldwide enterprise network.