Skip to content
You can now search across every topic, entity and event.What's new
FortiBleed
Concept

FortiBleed

FortiBleed is a credential-harvesting campaign identified by researcher Volodymyr Diachenko in June 2026 that compiled 86,644 Fortinet FortiGate credentials across 194 countries via credential reuse and traffic interception, attributed to a Russian-speaking actor with NATO-weighted targeting.

Last refreshed: 14 July 2026 · Appears in 1 active topic

Key Question

Four months quiet, then 12 ransomware hits: what triggered FortiBleed's use?

Timeline for FortiBleed

#11 16 Jul

Mentioned in: CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
#10 8 Jul

Underpinned confirmed ransomware deployments and administrator compromises

Cybersecurity: Threats and Defences: One operator ran both ransomware brands
#9 4 Jul

Mentioned in: BOD 26-04, a fortnight of triage

Cybersecurity: Threats and Defences
#9 1 Jul

Mentioned in: Lynx crew cashes in FortiBleed haul

Cybersecurity: Threats and Defences
#8 18 Jun

Assembled a profiled 86,644-credential target list running since February 2026

Cybersecurity: Threats and Defences: 86,644 Fortinet logins become a hit list
View full timeline →

Background

FortiBleed entered public view on 18 June 2026 when the UK NCSC and US CISA issued concurrent alerts after Ukrainian researcher Volodymyr Diachenko found a privately-held database of 86,644 Fortinet FortiGate firewall credentials spanning 194 countries. No zero-day was used. The operator harvested credentials from earlier Fortinet incidents and intercepted traffic on already-compromised devices, running the operation since at least February 2026, roughly four months before discovery. A 45-GPU cracking rig threw approximately 1.16 billion authentication attempts at 320,000 targets, indicating sustained, resourced infrastructure rather than a smash-and-grab.

What distinguishes FortiBleed is the metadata layered onto the credentials. The dataset logs organisation revenue bands, employee counts, and sector tags, the kind of profiling a ransomware crew would spend weeks building. Attribution points to a Russian-speaking group with NATO-weighted targeting, a posture analysts call intelligence preparation: acquire access quietly, hold it, and trigger it during a geopolitical window. Both agencies recommended factory-resetting affected FortiGate devices and rotating all credentials.

FortiBleed fits a pattern of edge-device exploitation that has become the dominant initial-access vector across this topic. Fortinet hardware had drawn CISA KEV entries in April 2026 for a separate SQL injection flaw. The operational model, credential harvest without exploit, is significant: it means the attacker's access survives Fortinet patching the underlying device vulnerabilities, because the logins themselves remain valid until individually rotated. For defenders, the lesson is that patching the device is necessary but not sufficient; credential rotation is the remediation the device patch cannot deliver.

SOCRadar confirmed in July 2026 that the harvest had crossed from a dormant hit list into live ransomware. The firm traced admin-level access to 409 targets and a completed attack chain on 354, with at least 12 confirmed ransomware deployments attributed to the INC Ransom and Lynx crews, who share code lineage and, SOCRadar found, one operator running both groups' negotiation panels. The scanning footprint reached roughly 11,250 FortiGate portals across more than 150 countries.

Common Questions
What is FortiBleed and how were the credentials stolen?
FortiBleed is a campaign that accumulated 86,644 Fortinet FortiGate credentials across 194 countries by reusing credentials from earlier Fortinet incidents and intercepting traffic on already-compromised devices. No zero-day exploit was used.Source: NCSC/CISA joint advisory, 18 June 2026
Why did NCSC and CISA issue alerts about FortiBleed on the same day?
Both agencies alerted on 18 June 2026 because the dataset had not been sold or published publicly, meaning the operator appeared to be holding credentials for a targeted operation rather than monetising them, consistent with state-adjacent intelligence preparation.Source: NCSC/CISA joint advisory, 18 June 2026
How do I know if my FortiGate is in the FortiBleed dataset?
Both NCSC and CISA advised organisations to assume compromise if running Fortinet FortiGate devices: factory-reset affected appliances and rotate all associated credentials regardless of whether specific devices appear in the dataset.Source: NCSC/CISA advisory recommendations, 18 June 2026
Is FortiBleed linked to a Russian state actor?
Attribution from NCSC and CISA points to a Russian-speaking group with NATO-weighted targeting. The decision to hold the dataset privately rather than sell it mirrors the intelligence-preparation posture attributed to state-adjacent actors such as Volt Typhoon.Source: NCSC/CISA joint advisory, 18 June 2026
Did the FortiBleed credentials get used in actual ransomware attacks?
Yes. SOCRadar confirmed in July 2026 that the harvest converted into at least 12 ransomware deployments, with admin-level access on 409 targets and a completed attack chain on 354.Source: SOCRadar
Is FortiBleed connected to INC Ransom and Lynx ransomware?
Yes. SOCRadar attributed the FortiBleed credential harvest to the Lynx ransomware crew, which shares code lineage and, as of July 2026, one operator with INC Ransom.Source: SOCRadar
Source Material