INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FortiBleed Attackers Exploit Firewalls to Steal Credentials

| 2026-06-23 12:34 MEDIUM LOW DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
The FortiBleed attack campaign, which began at least in February 2026, is believed to be carried out by Russian threat actors using a sniffer tool dubbed FortigateSniffer that turns compromised FortiGate firewalls into passive credential collectors. The attackers have targeted more than 430,000 FortiGate firewalls globally and have resulted in the breach of high-value targets such as a NATO-aligned defense contractor. Small to medium-sized businesses with fewer than 200 employees, particularly in the US and India, are among the key targets of this campaign. As a result of the attack, attackers have managed to create over 659 credential-harvesting pipelines using FortigateSniffer, resulting in the theft of more than 110 million credentials, including RADIUS, NTLM, and Kerberos material.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign BasedCampaign Based
Target & Sectors
NORTH_AMERICA NORTH_AMERICA defensedefense governmentgovernment
Incident Timeline
‎2026/06/23
Threat actors used FortigateSniffer to compromise hundreds of thousands of FortiGate firewalls, turning them into passive credential stealers.
victims 200 employees
infrastructure Fortigate
infrastructure 659 harvesting pipelines
data_breach 110 credentials
Tactical Metrics
Metrics
victims
200
Employees
Metrics
infrastructure
‎Fortigate
Affected Product
Metrics
infrastructure
659
Harvesting Pipelines
Metrics
data_breach
110,000,000
Credentials
Intelligence Sources