A financially motivated Russian-speaking initial access broker (IAB) is assessed to be behind the FortiBleed campaign, which has targeted over 430,000 FortiGate firewalls globally since February 2026. The actor uses a multi-stage pipeline involving reconnaissance, brute-forcing, credential sniffing, hash cracking, and data exfiltration, with a focus on SMBs and sectors like IT services.