
FortiBleed
FortiBleed is a credential-harvesting campaign identified by researcher Volodymyr Diachenko in June 2026 that compiled 86,644 Fortinet FortiGate credentials across 194 countries via credential reuse and traffic interception, attributed to a Russian-speaking actor with NATO-weighted targeting.
Last refreshed: 14 July 2026 · Appears in 1 active topic
Four months quiet, then 12 ransomware hits: what triggered FortiBleed's use?
Timeline for FortiBleed
Mentioned in: CISA's KEV list runs a month late
Cybersecurity: Threats and DefencesUnderpinned confirmed ransomware deployments and administrator compromises
Cybersecurity: Threats and Defences: One operator ran both ransomware brandsMentioned in: BOD 26-04, a fortnight of triage
Cybersecurity: Threats and DefencesMentioned in: Lynx crew cashes in FortiBleed haul
Cybersecurity: Threats and DefencesAssembled a profiled 86,644-credential target list running since February 2026
Cybersecurity: Threats and Defences: 86,644 Fortinet logins become a hit listBackground
FortiBleed entered public view on 18 June 2026 when the UK NCSC and US CISA issued concurrent alerts after Ukrainian researcher Volodymyr Diachenko found a privately-held database of 86,644 Fortinet FortiGate firewall credentials spanning 194 countries. No zero-day was used. The operator harvested credentials from earlier Fortinet incidents and intercepted traffic on already-compromised devices, running the operation since at least February 2026, roughly four months before discovery. A 45-GPU cracking rig threw approximately 1.16 billion authentication attempts at 320,000 targets, indicating sustained, resourced infrastructure rather than a smash-and-grab.
What distinguishes FortiBleed is the metadata layered onto the credentials. The dataset logs organisation revenue bands, employee counts, and sector tags, the kind of profiling a ransomware crew would spend weeks building. Attribution points to a Russian-speaking group with NATO-weighted targeting, a posture analysts call intelligence preparation: acquire access quietly, hold it, and trigger it during a geopolitical window. Both agencies recommended factory-resetting affected FortiGate devices and rotating all credentials.
FortiBleed fits a pattern of edge-device exploitation that has become the dominant initial-access vector across this topic. Fortinet hardware had drawn CISA KEV entries in April 2026 for a separate SQL injection flaw. The operational model, credential harvest without exploit, is significant: it means the attacker's access survives Fortinet patching the underlying device vulnerabilities, because the logins themselves remain valid until individually rotated. For defenders, the lesson is that patching the device is necessary but not sufficient; credential rotation is the remediation the device patch cannot deliver.
SOCRadar confirmed in July 2026 that the harvest had crossed from a dormant hit list into live ransomware. The firm traced admin-level access to 409 targets and a completed attack chain on 354, with at least 12 confirmed ransomware deployments attributed to the INC Ransom and Lynx crews, who share code lineage and, SOCRadar found, one operator running both groups' negotiation panels. The scanning footprint reached roughly 11,250 FortiGate portals across more than 150 countries.