Suspected Russian-speaking threat actors compromised over 30,000 Fortinet firewalls across 194 countries in a large-scale credential harvesting campaign dubbed FortiBleed. They used leaked passwords and passive network monitoring to collect credentials, then pivoted into internal networks.