Critical FortiBleed Vulnerability Compromises Over 70,000 Fortinet Firewalls in Active Enterprise Network Attacks
TL;DR
The "FortiBleed" Fallout: How 75,000 Firewalls Became an Open Door for Hackers
It’s the kind of nightmare scenario that keeps CISOs awake at night: a massive, automated campaign dubbed "FortiBleed" has effectively cracked open the front door to 75,000 Fortinet firewalls across the globe. We aren't talking about a niche exploit here. This incident has compromised roughly half of all internet-facing Fortinet infrastructure, leaving networks in 194 countries wide open.
The mechanics of the breach are chillingly straightforward. Attackers aren't necessarily hunting for zero-day exploits in the code; they’re hunting for credentials. By grabbing administrative configuration files, these actors have been able to waltz into enterprise networks with the keys to the kingdom.
Security researchers at Kudelski Security have been tracking the carnage, and the numbers are staggering. We’re looking at over 73,000 unique firewall URLs and upwards of 21,000 domains caught in the crosshairs. The sheer volume of the assault—1.16 billion credential attempts against FortiGate targets and another 2.1 billion against MSSQL servers—tells you everything you need to know about the scale of this operation. This isn't a surgical strike; it’s a carpet-bombing campaign.
The list of victims reads like a Fortune 500 roll call: Samsung, Comcast, Foxconn, Siemens, Lenovo, PwC, Accenture, and Oracle. And it gets worse. A Turkish NATO defense contractor reportedly had classified documents siphoned off after their infrastructure was compromised. The common thread? Most of these devices had their FortiGate Management Interface exposed to the public internet. In 2026, you’d think we’d know better, but here we are.

The "Patching Paradox"
Why did this happen on such a massive scale? It comes down to a nasty little trap researchers are calling the "Patching Paradox."
Fortinet eventually upgraded its credential storage to the robust PBKDF2 hashing algorithm. That’s the good news. The bad news? The update didn't retroactively re-hash existing passwords. If you updated your firmware but didn't manually log in to trigger a password reset, your credentials remained trapped in the old, vulnerable SHA-256 format.
It’s a classic case of "set it and forget it" biting back. Administrators assumed the update made them bulletproof, but the legacy hashes were still sitting there, waiting to be cracked.
Hudson Rock has provided data showing just how easily those configuration files gave up the ghost. The attackers, likely a sophisticated Russian-speaking syndicate, didn't need to be geniuses. They just needed a high-performance 45-GPU cluster to chew through those legacy hashes. Once they had the credentials, the "security" provided by standard password complexity was rendered completely irrelevant.
The Damage Report
| Category | Details |
|---|---|
| Total Impacted Devices | ~75,000 |
| Global Reach | 194 Countries |
| Primary Vector | Exposed Management Interface |
| Credential Vulnerability | Non-retroactive PBKDF2 hashing |
What Now?
If you’re running Fortinet gear, you need to stop reading this and start checking your logs. The "FortiBleed" campaign isn't slowing down, and if your management interface is staring out at the public internet, you’re basically inviting them in for coffee.
Here is your immediate checklist:
- Kill the Public Access: If your FortiGate Management Interface is reachable from the public internet, pull the plug. Restrict it to internal access only, immediately.
- Force the Re-hash: Don't trust that your firmware update did the heavy lifting. You need to perform a manual password reset across your administrative accounts to force the transition to PBKDF2.
- Hunt for Ghosts: Scan your logs for anything that looks weird. Look for unauthorized login patterns or configuration exports that shouldn't be there. If you see them, assume you've been breached.
- Verify Everything: Double-check that your firmware is current, but don't stop there. Confirm that the password update process has actually been completed.
The scale of this compromise is a harsh reminder that security isn't just about applying patches—it's about understanding the nuances of how those patches interact with your legacy environment. As the investigation into FortiBleed grinds on, the focus is shifting from "how did this happen?" to "what else did they take?"
For now, treat every Fortinet device in your fleet as a potential liability. The era of assuming your firewall is a fortress is officially over.