started · updated
Fortinet firewall credential leak exposes tens of thousands of VPN and admin passwords
A data leak dubbed “FortiBleed” has revealed VPN access information for about 73,900 firewall URLs and functioning administrator credentials for roughly 74,000 FortiGate firewalls. The leak spans 194 countries and was uncovered by security firms Arctic Wolf and SOCRadar, with researcher Kevin Beaumont estimating up to half of all Internet‑exposed FortiGates are affected.
The breach stems from legacy password‑hashing in older FortiOS versions that stored admin passwords as fast SHA‑256 hashes. Attackers first tried billions of credential combos from previous leaks, then harvested configuration files and cracked the hashes offline using GPU clusters. Although newer FortiOS releases (7.2.11, 7.4.8, 7.6.1) employ the stronger PBKDF2 algorithm, existing hashes remain until the administrator logs in again, meaning many installations stay vulnerable after an upgrade.
Fortinet has labeled the issue “uncritical” and no CVE has been issued, but security experts urge immediate remediation: reset all VPN and admin passwords, enforce multi‑factor authentication, restrict management interfaces to internal networks, and ensure administrators re‑authenticate post‑update. German companies such as Telekom and Mercedes‑Benz are among the estimated 120 affected German installations.