Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

86,644 Fortinet logins become a hit list

4 min read
16:08UTC

NCSC and CISA issued alerts on 18 June after a privately-held database of 86,644 FortiGate credentials across 194 countries surfaced. No zero-day was used.

TechnologyDeveloping
Key takeaway

Holding 86,644 profiled credentials privately signals careful targeting ahead, not a smash-and-grab.

The NCSC (the UK National Cyber Security Centre) and CISA both issued alerts on 18 June after a database of 86,644 Fortinet FortiGate firewall credentials, spanning 194 countries, surfaced in the criminal underground 1. The attackers used no zero-day. The operation, dubbed FortiBleed, harvested credentials from earlier Fortinet incidents and intercepted traffic on already-compromised devices, running since at least February 2. The discoverer, Ukrainian researcher Volodymyr Diachenko, dated his finding to 13 June 3.

What the dataset carries matters more than its scale. It logs organisation revenue bands, employee counts, and sector tags, the profiling a ransomware crew would otherwise spend weeks assembling, and it had not been dumped on any dark-web forum as of mid-June 4. A 45-GPU cracking rig threw roughly 1.16 billion authentication attempts at 320,000 targets 5. The revenue bands and sector tags give the operation away: an encryption crew does not need that metadata to lock files, but an intelligence operation needs it to prioritise. The attribution points to a Russian-speaking group with NATO-weighted targeting, and the decision to hold the data privately rather than sell it reads as preparation, not opportunism. That is the Volt Typhoon posture, the Chinese state-linked pre-positioning in US infrastructure: acquire access now, use it at a moment of the operator's choosing.

Edge devices keep opening the door. Check Point's VPN concentrator ran exploited for a month before its patch landed , and the FIRESTARTER Cisco implant survived every firewall patch thrown at it . The firewall is no longer only the way in; it is also the credential store. A leak with no exploit at all still earned two government alerts in a single day, because the harvested logins open the same doors a zero-day would, quietly and at national scale.

Deep Analysis

In plain English

Fortinet's FortiGate is one of the most widely deployed firewall appliances in the world, with tens of thousands of organisations relying on it to control access to their networks. In February 2026, someone began collecting the usernames and passwords used to log into 86,644 of these devices across 194 countries, without exploiting any known software flaw. They did it by reusing credentials leaked from other breaches and by intercepting network traffic. Researcher Volodymyr Diachenko found the database on 13 June. The detail is what makes it alarming: each entry includes the organisation's sector, revenue band, and employee count. That kind of profiling goes beyond what criminals need for a quick financial attack. It matches the preparation for a selective, targeted campaign, and the dataset skewed heavily towards NATO member countries.

Deep Analysis
Root Causes

Edge devices such as FortiGate firewalls and VPN concentrators carry structural credential-store vulnerabilities because their authentication architectures were designed for perimeter trust models that assumed internal networks were safe. When a device serves as both the authentication gateway and the credentials repository, a credential-reuse or traffic-interception attack bypasses authentication without exploiting any software flaw, leaving no CVE to patch.

Fortinet's credential plane went unmonitored for at least four months: the FortiBleed campaign ran since at least February 2026 without triggering vendor or customer detection. Neither Fortinet's telemetry nor most customers' monitoring extends to the credential-plane behaviour of their perimeter appliances.

The Check Point VPN exposure one month earlier followed the same pattern, with exploitation confirmed for a month before detection, confirming the credential layer of edge appliances as a systematic monitoring gap across multiple vendors.

What could happen next?
  • Risk

    The 86,644 credentials in private hands since at least February 2026 may be activated selectively rather than en masse; organisations in NATO-member defence, energy, or finance sectors face elevated risk of targeted access attempts that the FortiBleed dataset would facilitate.

    Immediate · Assessed
  • Consequence

    Fortinet faces a third credential-incident disclosure in 36 months; institutional investors and enterprise procurement teams are likely to apply a systematic credential-hygiene surcharge to Fortinet devices in risk assessments and contract renewals.

    Short term · Reported
  • Precedent

    FortiBleed demonstrates that edge-device credential planes can be harvested at scale without any software vulnerability, creating a monitoring requirement that CVE patching alone cannot satisfy: behavioural analysis of authentication-plane traffic to and from perimeter appliances.

    Medium term · Assessed
First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

NCSC· 24 Jun 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.