A newly discovered data leak has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs across 194 countries
A newly discovered data leak dubbed “FortiBleed” has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials …
BleepingComputerLawrence Abrams
Context & Ripple Effects
This disclosure follows a recurring Fortinet access-security pattern in the related coverage: a 2021 leak of roughly 500,000 VPN login credentials, actively exploited authentication-bypass flaws in 2022, and a large population of exposed, unpatched SSL VPN interfaces in 2023.
More recently, Fortinet disclosed that a critical FortiManager API flaw was being used in zero-day attacks to steal sensitive files. The new credential collection broadens the immediate concern from a software vulnerability to the security of VPN identities deployed across a large international footprint.
First-order effects
Organizations operating the listed Fortinet or FortiGate VPN endpoints need to treat the exposed credentials as potentially compromised, rotate credentials, and review VPN authentication and access logs.
Fortinet faces renewed customer-support and incident-response pressure, particularly where affected credentials remain valid or are tied to internet-facing remote-access systems.
Second-order effects
Security teams may accelerate adoption of stronger VPN access controls, such as multi-factor authentication and credential rotation processes, rather than relying on passwords associated with perimeter appliances.
The leak increases the operational burden on managed security providers and enterprise IT teams that must identify affected endpoints, validate exposure, and distinguish leaked credentials from credentials already changed or inactive.
Third-order effects
If repeated credential leaks and exploited perimeter flaws persist, remote-access security will increasingly be evaluated as an identity-management and continuous-monitoring problem, not solely as a firewall-patching task.
The pattern could further reward security architectures that reduce the value of a single VPN credential or exposed appliance; the corpus does not establish whether this leak will itself drive a lasting vendor-share shift.
The trend: This is another data point in the shift from perimeter-device trust toward identity-hardened, continuously monitored remote access.
UPDATE 🠖 FortiBleed looks bigger than first reported. Update: Hudson Rock says FortiBleed targeted 73,932 Fortinet firewall URLs across 194 countries, affecting 21,632 domains. The bigger risk: exposed FortiGate SSL VPNs may be used as listening posts to capture more [image]
‼️🚨 BREAKING: 320,000 Fortinet firewall devices have been targeted in a campaign that has been dubbed ‘FortiBleed’. Attackers were able to confirm 75,000 working credentials against the admin and SSL VPN interfaces. The victims include really big names like Samsung, Oracle, [imag…
🚨 Meet #FortiBleed. If you are running Fortinet, it is time to check your logs. Our Threat Research team just uncovered a massive, active campaign with 30,000+ compromised Fortinet firewall credentials across 194 countries. The US is target #2. Banks, telecoms, and gov
Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action. Thousands of top vendors instances are listed in the files like this (see screenshot). …
Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action. Thousands of top vendors instances are listed in the files like this (see screenshot). …
Firewall credentials are not an IT hygiene issue. They are enterprise risk. — BleepingComputer reports that leaked Fortinet VPN credentials may affect more than 73,000 firewall URLs worldwide. …