FortiBleed: When Tens of Thousands of Firewalls Become an Open Door
FortiGate firewalls exist to protect corporate networks. FortiBleed shows what happens when the firewall itself becomes the attack surface – and opens the door.
- by blacklens.io Team
- Published
- 3 min read

FortiGate firewalls protect corporate networks. That is their sole purpose. What FortiBleed shows: when the firewall itself becomes the attack surface, it no longer protects – it opens up.
What is FortiBleed?
FortiBleed is not a single breach. It is an industrialised harvesting operation against internet-exposed Fortinet firewalls and SSL VPN gateways. The dataset was discovered in mid-June 2026 by security researcher Volodymyr "Bob" Diachenko.
The scale is extraordinary – even though the exact figures vary by source and are still changing, as the campaign was still active at the time of publication. Security researchers who analysed the leaked dataset estimate the number of affected FortiGate devices at somewhere between 30,000 and 75,000. The entries it contains can be attributed to around 21,600 domains in 194 countries – a cross-section of global corporations, public authorities and critical infrastructure operators across almost every industry.
How the attack worked
The attack follows an automated, self-reinforcing chain. First, the internet is scanned for reachable FortiGate devices – above all SSL VPN endpoints and management interfaces. Against each device found, the attackers then test a curated list of known passwords. A successful login is not followed by a noisy attack – instead, the compromised device is used as a silent "listening post": it sits at the network perimeter and reads the traffic passing through in order to harvest further credentials. These flow back into the scanner and compromise the next device. The system feeds itself.
The password list being tested is not random. It consists of credentials that had already leaked in earlier Fortinet incidents and via infostealer logs – many organisations never changed their passwords after a previous incident. In addition, according to Diachenko's reconstruction, the attackers intercepted SSL VPN authentication hashes and cracked them offline with a GPU cluster (a Hashtopolis-managed setup of around 45 GPUs has been reported).
As things stand, this is not a confirmed zero-day. How the configuration data originally left the devices remains open: candidates include known but unpatched vulnerabilities (in particular CVE-2026-24858, a FortiCloud SSO SAML bypass with a CVSS score of up to 9.8), a still-unknown flaw, infostealer credentials, or a combination of these. A further contributing factor is that on many devices admin passwords are still stored in the older SHA-256 format – namely wherever admins never logged in again after a firmware update. In any case, the core of the problem remains the same: exposed management interfaces and reused or crackable credentials.
The role of infostealers
A significant share of the credentials does not come from classic brute force but from infostealer campaigns. Infostealer malware on employee devices steals saved VPN credentials and passwords from browsers and password managers before they end up in dark web forums and dumps. In many cases these credentials enabled a valid login without any brute force at all.
That also makes FortiBleed a dark web monitoring topic: the infostealer activity that led to these credentials was visible in the relevant forums and dumps – to anyone actively looking there.
What helps – and why visibility is decisive
This is exactly where blacklens.io comes in. Dark Web Monitoring detects when credentials or infostealer activity affect your own company – the Emerging Threat Notification System informs you proactively, before someone else reacts. Continuous attack surface analysis shows which systems are really reachable from the outside – including the ones nobody internally remembers any more.
Frequently asked questions
- FortiBleed is an industrialised credential-harvesting operation against internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways, discovered in mid-June 2026 by security researcher Volodymyr Diachenko. Estimates put the number of affected devices between 30,000 and 75,000, spread across roughly 21,600 domains in 194 countries.
More articles

What First? Intelligent Vulnerability Prioritisation with blacklens
What first, why, and how? blacklens turns open findings into a prioritised remediation plan – sorted by risk reduction, with context on every finding.
- 5 min read

Access Broker Economy: When Network Access Is Sold on the Dark Web
Ransomware attacks rarely start with the ransomware. They start with a compromised account or stolen credentials – sold on by Initial Access Brokers.
- 2 min read

Dark Web Monitoring: An Indispensable Tool Against Cyber Threats
Discover how blacklens.io uses dark web monitoring to detect cyber threats early and protect companies from attacks originating in the darknet.
- 4 min read
See your attack surface within 24 hours.
We set up your workspace and walk you through the first findings.
- 14 days free, all features
- No credit card required
- We walk you through your first findings