INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Russian Hackers Exploit FortiBleed Vulnerability to Harvest Credentials

| 2026-06-22 10:25 MEDIUM LOW DATA BREACH
Executive Summary
AI-generated
On June 22, 2026, a large-scale Russian credential-harvesting operation known as FortiBleed targeted over 430,000 FortiGate devices globally, resulting in the theft of more than 110 million credentials. The campaign is believed to be financially motivated and has already led to confirmed breaches, including one involving a NATO-aligned defense contractor. The attackers used a five-phase attack chain that included credential sourcing, mass reconnaissance, initial access through SSH brute-force and credential stuffing, and lateral movement using a Golang-based tool called FortigateSniffer. This tool abuses legitimate diagnostic commands to capture authentication traffic without deploying malware, with the sniffer only running during normal business hours in Moscow Time. The campaign is still actively sniffing over 19,000 devices as of the time of writing, part of a broader pool of 80,553 identified targets.
Technical Mitigations AI-generated
• Password Policies (ATT&CK mitigation for Credential Stuffing): Refer to NIST guidelines when creating password policies. • User Account Management (ATT&CK mitigation for Credential Stuffing): Proactively reset accounts that are known to be part of breached credentials either immediately, or after detecting bruteforce attempts. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

va•••••.ai
so•••••.io
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation FortiBleedOperation FortiBleed
Target & Sectors
EUROPE EUROPE MIDDLE_EAST MIDDLE_EAST LATAM LATAM NORTH_AMERICA NORTH_AMERICA technologytechnology
Incident Timeline
‎2026/06/22
Threat actors used a combination of tools, including Masscan and custom Shodan_Recon tool, to target 430,000+ FortiGate devices globally.
infrastructure Fortigate
financial 430,000 devices
data_breach 110 credentials
infrastructure 659 pipelines
infrastructure Linux
infrastructure 150 additional servers
infrastructure 19,000 devices
victims 80,553 identified targets
victims 200 employees
Tactical Metrics
Metrics
infrastructure
‎Fortigate
Affected Product
Metrics
financial
430,000
Devices
Metrics
data_breach
110,000,000
Credentials
Metrics
infrastructure
659
Pipelines
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
150
Additional Servers
Metrics
infrastructure
19,000
Devices
Metrics
victims
80,553
Identified Targets
Metrics
victims
200
Employees
Intelligence Sources