Threat Intelligence
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
Cyber RTJune 19, 20263 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned Fortinet customers to secure FortiGate appliances against the FortiBleed campaign, targeting 86,644 devices. Russian-speaking threat actors exploit default and organization-specific credentials, impacting telecom, government, and education sectors globally. The attack uses leaked passwords and monitors network traffic to gather more credentials. CISA advises password resets, strong policies, and multi-factor authentication to mitigate risks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to Fortinet customers using FortiGate appliances to secure their systems against a widespread malicious campaign known as FortiBleed. This campaign, attributed to Russian-speaking threat actors, has compromised 86,644 internet-accessible devices as of June 19, 2026. The attack primarily targets generic admin accounts and built-in Fortinet system accounts, which together constitute a significant portion of the compromised credentials.
SOCRadar's data indicates that the failure to rename default accounts or rotate factory credentials has provided attackers with an easy target list, reducing the need for brute force attacks. Notably, organization-specific accounts also make up a large portion of the breached credentials, suggesting that attackers have accessed accounts created by organizations, potentially from prior breaches where passwords were not updated.
The sectors most affected by this breach are telecom, government, and education, with significant exposures reported in countries such as India, the U.S., Mexico, Colombia, and Thailand. The attackers have been mass-scanning the internet for Fortinet remote login endpoints and using a custom tool to attempt login with known credentials, aiming to gain unauthorized access.
The attack is automated and follows a two-step process. Initially, attackers use a curated list of leaked Fortinet passwords to gain access to devices. Once access is secured, they monitor network traffic to collect additional credentials, which are then used to compromise more devices. The attackers verify each credential before adding it to a database of confirmed logins, creating a vast repository of working credentials.
The U.K. National Cyber Security Centre (NCSC) has characterized FortiBleed as a global campaign targeting Fortinet firewalls and VPN gateways through methods like brute-force attacks and credential stuffing. The attackers likely exploited older credential hashing mechanisms and the way credentials have been stored in FortiGate configuration files to execute this large-scale attack.
Fortinet has responded by stating that the data involved is likely from previous incidents and not related to any current advisory. They emphasize the importance of following best practices, such as regularly rotating security credentials and enabling multi-factor authentication (MFA). CISA has provided specific recommendations, including terminating active sessions, resetting passwords, enforcing strong password policies, and enabling phishing-resistant MFA.
The FortiBleed incident was first uncovered by security researcher Volodymyr "Bob" Diachenko, who found a server containing a database of working login credentials for thousands of firewalls and VPN gateways across 194 countries. This breach highlights the critical issue of credential reuse and poor password hygiene, underscoring the vulnerability of perimeter security appliances as targets for gaining initial access to enterprise environments.


