< Back to all clusters
[TECHNOLOGY] · Germany, Denmark, United States · 2 sources

started · updated

FortiBleed hack compromises over 73,000 firewalls in 194 countries

A coordinated cyber‑attack dubbed “FortiBleed” has compromised 73,932 Fortinet firewall and VPN devices across 194 nations. The breach exploited a flaw where SHA‑256 password hashes were not migrated to the more secure PBKDF2 standard after a firmware update, allowing attackers to harvest credential data.

Security researchers identified that a Russian‑language hacking group used more than a billion login attempts and a 45‑GPU cluster to crack the exposed hashes. The compromised firewalls are now being used as listening posts to monitor corporate network traffic and potentially gain further access.

High‑profile victims include global corporations such as Samsung, Siemens, Lenovo, Oracle, Foxconn and Comcast. The Danish pharmaceutical giant Novo Nordisk confirmed a breach, reporting that the attackers stole 1.3 TB of data—including clinical trial information and a 16.7 GB AI model—and demanded a €25 million ransom. Additional leaks involved companies like Kodak and public infrastructure entities, with threats to release millions of personal records.

Authorities urge organizations to verify whether their Fortinet devices are affected, migrate password hashes to PBKDF2, and isolate any compromised equipment immediately.