< Back to situations

This situation has concluded

It was preserved as a record on August 4; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.

[SITUATION] · [QUIET] · [TECHNOLOGY]

9 clusters · 37 sources · 18 days · First seen · Last updated

FortiBleed campaign spreads to UK, Belgium, maritime

Overview

The FortiBleed operation, first identified in mid‑June 2026, uses a Golang sniffer tool to harvest authentication credentials from Fortinet FortiGate firewalls and SSL‑VPN gateways. By late June, over 430,000 devices were compromised, with more than 19,000 firewalls actively sniffing traffic. Attackers sell the harvested logins on underground markets, relying on weak passwords and missing multi‑factor authentication rather than a software flaw.

Compromised firewalls have been found in Belgium, Namibia, the United States, Mexico, South Africa and other regions, providing footholds for Active Directory enumeration and lateral movement. In early July, the campaign was linked to a large‑scale breach of UK government email accounts, affecting the Foreign Office, local councils, the NHS and other critical‑infrastructure providers. Over 80,000 firewall credentials and 86,000 administrator logins were stolen, with offers on dark‑web forums reaching $60,000.

A July 5 report added that the breach also exposed more than 250 shipping‑related organisations; 41.5 % of the leaked credentials belong to shipping and freight companies, and 703 satellite‑linked IP addresses used by maritime communication providers were compromised. The UK National Cyber Security Centre has issued urgent alerts urging password resets, MFA enablement and termination of active admin sessions.

Further analysis released on July 4 indicated that Russian‑linked hackers used the stolen credentials to access email accounts of Foreign Office staff, local officials and IT personnel at British embassies in Thailand, Mauritius, Derbyshire and Waltham Forest. The leak also covered energy providers and pharmaceutical suppliers. No definitive state involvement has been proven, but authorities warn the dump creates a clear pathway for ransomware groups to target hospitals, energy grids and other critical services. The U.S. Cybersecurity and Infrastructure Security Agency issued parallel guidance.

Timeline

  1. 3 months ago

    [CRIME] 14 sources
    Russian hackers use FortiBleed to breach UK government and maritime networks

    FortiBleed exposed 86,000+ credentials, breaching UK government email accounts and maritime firms; stolen log‑ins are sold on the dark web, prompting urgent security alerts.

  2. 3 months ago

    [TECHNOLOGY] 3 sources
    Belgian firms face large‑scale cyber attacks due to third‑party vulnerabilities

    Hundreds of Belgian companies were hit by large‑scale cyber attacks exploiting Fortinet firewalls, highlighting third‑party risk and the need for greater cyber‑resilience.

  3. 3 months ago

    [TECHNOLOGY] 4 sources
    FortiBleed Campaign Compromises Tens of Thousands of Fortinet Firewalls Globally

    FortiBleed has compromised up to 73,000 Fortinet firewalls in 194 countries using stolen credentials, prompting calls for MFA and password resets worldwide.

  4. 3 months ago

    [TECHNOLOGY] 4 sources
    FortiBleed campaign harvests credentials from FortiGate firewalls worldwide

    SOCRadar reports the FortiBleed campaign actively harvesting credentials from over 430,000 FortiGate firewalls worldwide using a custom sniffer tool and selling access to attackers.

  5. 3 months ago

    [TECHNOLOGY] 3 sources
    FortiBleed cyber‑attack compromises tens of thousands of Fortinet firewalls worldwide

    CISA warns that the FortiBleed campaign has breached 74‑86k Fortinet firewalls worldwide, exploiting leaked admin credentials across telecom, government and education sectors in multiple countries; immediate MF

  6. 3 months ago

    [TECHNOLOGY] 2 sources
    FortiBleed credential‑spraying campaign compromises ~75,000 FortiGate firewalls globally

    The FortiBleed campaign performed billions of login attempts, compromising about 75,000 FortiGate firewalls in dozens of countries, prompting alerts for hardening and removal of public VPN exposure.

  7. 3 months ago

    [TECHNOLOGY] 4 sources
    Fortinet firewall credential leak exposes tens of thousands of VPN and admin passwords

    The FortiBleed leak exposes VPN and admin credentials for ~74,000 FortiGate firewalls in 194 countries, stemming from old SHA‑256 hashing; experts advise password resets, MFA, and stricter access controls.

  8. 3 months ago

    [TECHNOLOGY] 5 sources
    Fortinet firewalls hijacked worldwide in FortiBleed credential‑harvesting campaign

    The FortiBleed campaign breached 30‑75 k Fortinet firewalls in 194 countries, affecting Fortune 500 firms and US, Indian, Taiwanese and Mexican agencies via brute‑forced passwords, with ties to a Russian‑linked

  9. 3 months ago

    [TECHNOLOGY] 2 sources
    FortiBleed hack compromises over 73,000 firewalls in 194 countries

    The FortiBleed campaign exploited a password‑hash flaw in Fortinet firewalls, compromising 73,932 devices in 194 countries and affecting firms such as Samsung, Siemens and Novo Nordisk, which faces a €25 M rans

Sources

asiapacificsecuritymagazine.com · bleepingcomputer.com · blogspan.net · borncity.com · ca.sports.yahoo.com · carriermanagement.com · clovermedia.jp · cryptobriefing.com · cybersecurity-news.de · ecofinagency.com · esecurityplanet.com · express.be · finanzen.at · finanzen.net · fr.businessam.be · galucomunicacion.com · hna.de · internetpost.it · it-boltwise.de · itnerd.blog · kreiszeitung.de · kurierverlag.de · ledecodeur.ch · leinetal24.de · mannheim24.de · memeburn.com · merkur-online.de · moncloa.com · nationalcybersecurity.com · op-online.de · security.nl · speedskating.co.nz · thehackernews.com · thesheffieldpress.com · ticmagazine.bf · wochentlich.de · wor.com