started · updated
Fortinet firewalls hijacked worldwide in FortiBleed credential‑harvesting campaign
A coordinated cyber‑crime operation dubbed “FortiBleed” has compromised tens of thousands of Fortinet firewalls and VPN gateways across 194 countries. Researchers estimate between 30,000 and 75,000 devices were accessed, allowing attackers to use the compromised firewalls as listening posts and to harvest additional credentials for deeper network intrusion.
The breach affected a broad range of organisations, including Fortune 500 firms such as Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens and PwC, as well as government agencies in the United States, India, Taiwan, Puerto Rico and Mexico. The attackers did not exploit a new software flaw; instead they scanned for internet‑exposed devices and brute‑forced reused or previously leaked passwords. The campaign’s infrastructure included automation scripts and a database of verified credentials, and researchers noted Russian‑language instructions, suggesting involvement of a Russian cyber‑crime group.
Fortinet confirmed it was aware of a third‑party credential‑harvesting effort and said the activity was not tied to any recent vulnerability advisory. Security firms Hudson Rock, SOCRadar and Securitydiscovery highlighted the scale of the operation and warned that routine hardening and multi‑factor authentication are essential defenses for edge devices.