FortiBleed: 74,000 Fortinet Admin Credentials Cracked Post-Patching
- CVE ID
- N/A
- Affected Products / Orgs
- Organizations with Fortinet devices that did not rotate admin credentials after patching prior vulnerabilities.
Overview
A significant cybersecurity incident, dubbed “FortiBleed,” has revealed that attackers successfully cracked over 74,000 administrative credentials associated with Fortinet FortiGate firewalls and VPN gateways. This large-scale compromise stems not from a new, unpatched vulnerability in Fortinet products, but from a critical oversight in post-incident security hygiene: the failure of organizations to rotate administrative passwords after patching previously exploited vulnerabilities. Researchers disclosed this campaign on July 19, 2026, highlighting a pervasive gap in incident response protocols. The credentials were derived from configuration backup files that were exfiltrated before patches for earlier vulnerabilities were applied.
Technical Details
The FortiBleed campaign exploits a common, yet often overlooked, vulnerability in incident response: the assumption that applying a patch fully resolves a security incident. While organizations diligently applied vendor fixes for prior vulnerabilities affecting Fortinet devices and even rotated API keys, many neglected to reset their core administrative passwords. Attackers, having previously exfiltrated configuration backup files from these systems, leveraged this oversight. These backup files contained hashed administrative credentials. Utilizing powerful GPU clusters, the threat actors were able to crack these hashes offline at scale, converting them into plaintext administrative passwords.
This technique is highly effective because modern GPU-accelerated cracking tools can break most password hashes in a matter of hours or days, depending on the algorithm and password complexity, especially if weak or common passwords are in use. Fortinet itself acknowledged in June 2026 that the activity involved threat actors reusing credentials from previous incidents (FG-IR-26-060, FG-IR-25-647) and employing brute-force techniques against devices with weak password hygiene and no multi-factor authentication (MFA).
The FortiBleed campaign represents the fourth distinct Fortinet security event in 2026, demonstrating a persistent targeting of the vendor’s products. Earlier in the year, AI-assisted exploitation of FortiGate was reported in February, followed by a FortiClient EMS endpoint manager takeover in early June, and FortiSandbox security appliance exploitation in mid-June. These incidents collectively underscore that addressing vulnerabilities in isolation, without a holistic security posture review, leaves organizations exposed.
Real-World Impact
The immediate impact of the FortiBleed campaign is severe. With over 74,000 valid administrative credentials exposed, affected organizations face the imminent threat of unauthorized access to their critical network infrastructure. FortiGate devices typically serve as an organization’s first line of defense, acting as firewalls and VPN gateways, controlling access to the internal network. Compromise of these devices via administrative credentials can grant attackers deep access, bypassing perimeter defenses.
This level of access can lead to a cascade of further malicious activities, including:
- Data Theft: Direct access to network traffic and internal systems can facilitate the exfiltration of sensitive organizational data, intellectual property, and customer information.
- Lateral Movement: Attackers can use the compromised FortiGate devices as a pivot point to move laterally within the network, escalating privileges and targeting other critical assets.
- Ransomware Deployment: The FortiBleed credentials could serve as an initial access vector for ransomware groups, potentially leading to widespread system encryption and operational disruption. Reports suggest connections between the threat actors behind FortiBleed and active ransomware groups like Lynx and INC.
- Systemic Compromise: Given that Fortinet products often manage an organization’s edge, their compromise could lead to a complete breakdown of network security, impacting business continuity and data integrity.
- Reputational Damage and Regulatory Fines: Organizations suffering breaches due to known, preventable oversights like unrotated credentials may face significant reputational harm and substantial regulatory penalties, particularly if sensitive data is compromised.
Threat Landscape
The FortiBleed incident is a stark reminder of the evolving threat landscape, where the focus is shifting from solely exploiting zero-day vulnerabilities to leveraging operational security gaps and human factors. It highlights the crucial role of post-exploitation hygiene, especially credential management, in the broader incident response lifecycle. The fact that the affected devices were already patched against the original vulnerabilities emphasizes that patching alone is insufficient if other attack surfaces, such as stolen configuration files or unrotated credentials, are not simultaneously addressed.
This incident also reflects a broader trend of systematic targeting of edge device vendors whose products facilitate network administrative access. As organizations increasingly rely on a complex array of interconnected systems, the security of these “edge” devices, which connect internal networks to the internet, becomes paramount. Threat actors are increasingly sophisticated, combining multiple attack vectors—from initial vulnerability exploitation to credential harvesting and brute-forcing—to achieve their objectives. The use of AI in exploiting FortiGate and other products in 2026 also points to an acceleration of attacker capabilities.
Remediation
Organizations impacted by or potentially vulnerable to the FortiBleed campaign must undertake immediate and comprehensive remediation steps:
- Terminate Sessions and Reset Credentials Immediately: All active administrative and VPN sessions on Fortinet devices, especially internet-facing ones, must be terminated. Following this, all Fortinet VPN and administrative passwords must be reset. Enforce strong, unique password policies for all accounts.
- Implement Multi-Factor Authentication (MFA): If not already in place, implement MFA for all administrator and VPN user accounts on Fortinet devices. This adds a critical layer of security, making it significantly harder for attackers to leverage stolen or cracked passwords.
- Audit Configuration Backups: Treat configuration backup files as crown jewels. They contain sensitive information, including hashed credentials, certificates, and network architecture details. Ensure these files are encrypted, access-controlled, and stored securely, separate from the live environment.
- Review Logs for Anomalous Activity: Proactively review firewall, VPN, authentication, and domain controller logs for any signs of lateral movement, unusual access attempts from unknown IP addresses, suspicious account creation, or unauthorized configuration changes.
- Secure Credential Storage: Ensure Fortinet devices are configured to use robust hashing algorithms like PBKDF2 for storing administrator credentials. Remove or deprecate weaker, legacy hashing methods.
- Reduce Attack Surface: Limit management access to Fortinet devices from the public internet. Where remote management is necessary, restrict access to specific, whitelisted IP addresses or use a secure jump box.
- Conduct Comprehensive Incident Response Planning: This incident underscores the necessity of a holistic incident response plan that extends beyond patching. It must include clear protocols for credential rotation, log analysis, and verification of system integrity after any security event, assuming potential data exfiltration.
By proactively addressing these areas, organizations can significantly enhance their resilience against credential-based attacks and ensure that patching efforts are not undermined by subsequent exploitation of lingering security gaps.
Related content
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call