← Back to feed
Threat Actors & CampaignsEmerging1 sourceJun 24, 2026 · 00:00via Recorded Future

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems

Brief

A dataset containing valid administrative and VPN credentials for tens of thousands of Fortinet FortiGate firewalls has been attributed to a Russian-speaking threat group, with confirmed impacts across government, critical infrastructure, and multinational corporations. Organizations should verify exposure immediately and rotate credentials.

Latest Updates

Based on analysis by Insikt Group, we have determined that at least two threat actors are attempting to sell data allegedly from the FortiBleed campaign impacting FortiGate VPN credentials. Also, based on analysis by Insikt Group, we assess that only one of the two sellers of this FortiBleed data is likely credible.

Read more on Recorded Future