The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to Fortinet customers following the discovery of a widespread credential-stuffing campaign dubbed FortiBleed. As of June 19, 2026, the campaign has compromised 86,644 internet-accessible FortiGate devices globally, with the top impacted sectors being telecom, government, and education. The most exposures are located in India, the U.S., Mexico, Colombia, and Thailand.
According to SOCRadar, generic admin accounts (35%) and built-in Fortinet system accounts (28.3%) account for the majority of compromised credentials, while organization-specific accounts make up 36.7%. The threat actors, believed to be Russian-speaking, mass-scanned the internet for Fortinet remote login endpoints and used a bespoke tool to spray known login and password combinations. The attack is fully automated and self-sustaining: after gaining access, the attackers passively monitor network traffic to collect additional credentials, which are then used to compromise more appliances. The credentials are verified before being added to a database of confirmed working logins.
Hudson Rock noted that the scale of the breach touches nearly every sector of the global economy. The U.K. National Cyber Security Centre (NCSC) described FortiBleed as a global campaign targeting internet-facing Fortinet firewalls and VPN gateways using brute-force, dictionary attacks, and credential stuffing. Arctic Wolf highlighted that older credential hashing mechanisms (SHA-256) may have been exploited, as Fortinet introduced PBKDF2-based hashing only in FortiOS 7.2.11, 7.4.8, and 7.6.1, leaving many organizations with legacy hashes.
Fortinet stated that the data likely involves resharing from previous incidents and brute-forcing, not a current incident. CISA recommends terminating all active SSL VPN and administrative sessions, resetting all passwords, enforcing strong password policies, using PBKDF2, enabling phishing-resistant MFA, reviewing logs, and reducing the attack surface. The campaign was first discovered by security researcher Volodymyr “Bob” Diachenko, who found a server containing the database of working credentials for devices across 194 countries.
CVEs: CVE-2026-24858, CVE-2025-59718, CVE-2025-59719, CVE-2026-11645
Attack groups: Russian-speaking threat actors
Companies: Fortinet, SOCRadar, Hudson Rock, Arctic Wolf, NCSC
Events: FortiBleed campaign
Original source: thehackernews.com