started · updated
FortiBleed Campaign Compromises Tens of Thousands of Fortinet Firewalls Globally
The FortiBleed credential‑compromise campaign has targeted internet‑exposed Fortinet FortiGate firewalls and SSL VPN gateways in at least 194 countries. Researchers estimate that tens of thousands of devices – up to roughly 73,000 – have been accessed using stolen or reused administrator and VPN credentials. The operation relies on credential stuffing, password‑spraying, offline password cracking and an automated pipeline dubbed the CyberStrike Harvester, rather than a new software vulnerability.
Cases identified include more than 270 Belgian organisations, 13 Namibian entities, and similar exposure in the United States, Mexico, South Africa and other regions. Cybersecurity firms estimate over 86,000 valid Fortinet credentials remain exposed worldwide. Compromised firewalls give attackers footholds to enumerate Active Directory, access SMB shares, and move laterally within corporate networks.
Fortinet says the activity does not stem from a fresh flaw and has begun notifying affected customers. The vendor advises immediate password resets, enabling multi‑factor authentication, applying the latest firmware updates and restricting internet‑facing management interfaces. The campaign underscores the risks of password reuse and inadequate MFA across critical infrastructure sectors such as government, finance, healthcare and telecommunications.