Cybercriminals Breach Tens Of Thousands Of Fortinet Firewalls In FortiBleed Credential-Harvesting Campaign
Image: The Register

Cybercriminals Breach Tens Of Thousands Of Fortinet Firewalls In FortiBleed Credential-Harvesting Campaign

17 June, 2026.Technology and Science.8 sources

The story in 15 seconds

  • FortiBleed compromised tens of thousands of Fortinet firewalls and VPN devices globally.
  • Attackers used weak or unchanged passwords, not zero-day exploits.
  • Reported victims range from 30,000 to 75,000 devices.

The divide · 1 of 3

CVE/patch-failure attribution vs credential-reuse theft

Changes mitigation from CVE-patching focus to credential-rotation and exposure control.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
8 sources
Other
6
Local Western
1
Western Mainstream
1

Other

Business Insider España
Business Insider España

Cybersecurity salaries, laid bare: this is what the 24 most well-known companies in the sector in the US pay their professionals, from CrowdStrike to Palo Alto Networks

17 June, 2026

Read the original →
Dark Reading
Dark Reading

Sweeping Credential-Harvesting Heist Compromises 30K+ Fortinet Devices

16 June, 2026

Read the original →
Escudo Digital
Escudo Digital

Alerta en Fortinet: los cortafuegos FortiGate parcheados han sido hackeados

17 June, 2026

Read the original →
InfoStealers
InfoStealers

FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure

17 June, 2026

Read the original →
SOCRadar® Cyber Intelligence Inc.
SOCRadar® Cyber Intelligence Inc.

FortiBleed: The Compromise of 30,000 Fortinet Firewalls

16 June, 2026

Read the original →
The Register
The Register

Massive password-stealing attack hits 75k Fortinet firewalls

17 June, 2026

Read the original →

Local Western

mezha.net
mezha.net

Hackers breach tens of thousands of Fortinet firewalls and steal credentials

17 June, 2026

Read the original →

Western Mainstream

TechCrunch
TechCrunch

Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world

17 June, 2026

Read the original →

Full story

FortiBleed and FortiGate

Cybercriminals have compromised tens of thousands of Fortinet firewalls and VPNs in an ongoing campaign dubbed FortiBleed, according to TechCrunch and cybersecurity firms Hudson Rock and SOCRadar.

Although most sectors have suffered from the coronavirus crisis, the cybersecurity industry continues hiring in the United States in an effort to fill it with more talent

Business Insider EspañaBusiness Insider España

TechCrunch reports that the campaign “appears to not involve abusing any unknown vulnerability,” instead relying on companies not changing passwords for internet-exposed Fortinet systems.

Image from Business Insider España
Business Insider EspañaBusiness Insider España

SOCRadar describes the compromise chain as self-sustaining, writing, “The system feeds itself,” after attackers use a compromised device as a listening post to collect additional credentials.

TechCrunch adds that Fortinet spokesperson Tiffany Curci said the company is “aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways,” and Fortinet said the data involved is “a resharing of data from previous incidents, as well as bruteforcing of credentials.”

Scale, targets, and regions

Hudson Rock and SOCRadar’s reporting diverges on scale, with TechCrunch saying Hudson Rock found evidence that more than 73,000 unique Fortinet URLs have been hacked while SOCRadar said the total of hacked devices is more than 30,000.

TechCrunch lists companies whose systems were attacked, including Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC, and it says the countries with the most affected devices are India, the United States, Taiwan, and Mexico.

Image from Escudo Digital
Escudo DigitalEscudo Digital

SOCRadar’s report says its attacker database contains login credentials for more than 30,791 devices belonging to companies and government organizations across 194 countries, and it warns that “If your organization uses a Fortinet firewall or VPN product and appears in this dataset, treat your network perimeter as already compromised and act immediately.”

Dark Reading similarly frames the operation as credential harvesting rather than a Fortinet flaw, quoting SOCRadar that “There’s no zero-day, no exploit, no actual 'bleed.'”

US cyber rules and Fortinet response

Escudo Digital ties the issue to a vulnerability identified as CVE-2025-59718 and says Fortinet distributed FortiOS 7.4.9 in December and later 7.4.10, while administrators reported malicious access even with those versions installed.

Escudo Digital also says the US Cybersecurity and Infrastructure Security Agency included the vulnerability in its list of “fallos activamente explotados,” and that the order requires federal agencies to apply corrections within “un plazo máximo de una semana.”

Meanwhile, SOCRadar rates FortiBleed as Critical and says its researchers detected an operational server of a hacking group, adding that the attacker’s database contains verified, working usernames and passwords tested and confirmed by the attackers themselves using automated tools running around the clock.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Technology and Science