/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A hacker has posted a list of usernames, passwords, IP addresses and SSH keys of 900+ Pulse Secure VPN enterprise servers on a Russian-speaking hacker forum

EXCLUSIVE: The list has been shared on a Russian-speaking hacker forum frequented by multiple ransomware gangs.

ZDNet Catalin Cimpanu

Context & Ripple Effects

This dump is not an isolated incident but the latest entry in a pattern of VPN credential leaks that has been building since at least the 2019 wave of attacks on Pulse Secure and Fortinet VPN appliances right after critical flaws went public. The forum in question matters because it is frequented by multiple ransomware gangs, turning a raw credential list into ready-made initial access for ransomware operators.

The same playbook recurs across vendors and years: hackers later leaked roughly 500K Fortinet VPN logins with some confirmed valid, and an even larger collection of FortiGate credentials surfaced covering firewall URLs worldwide — evidence that VPN appliance credentials are treated as a standing commodity in criminal markets.

First-order effects

  • Enterprises running the 900+ listed Pulse Secure servers face immediate risk of unauthorized remote access, since usernames, passwords, IPs and SSH keys are now public to ransomware-affiliated buyers.
  • Pulse Secure's incident response teams must treat every server on the list as compromised until credentials and keys are rotated.

Second-order effects

  • Ransomware gangs gain a low-cost entry path into corporate networks, bypassing phishing entirely by logging in with stolen VPN credentials.
  • Security teams will likely accelerate moves toward credential-rotation policies and multi-factor authentication on VPN gateways, pressuring vendors to harden default configurations.

Third-order effects

  • If the pattern holds — from the Pulse Secure dump through repeated Fortinet leaks — VPN appliances consolidate as the preferred initial-access vector for ransomware, pushing enterprises to treat edge-device credential hygiene as a board-level control rather than an IT task.
  • Law enforcement's seizure of criminal-market VPN infrastructure shows authorities responding to this ecosystem, but the recurring vendor-side leaks suggest regulation of enterprise appliance security practices may follow.

The trend: Enterprise VPN appliances are becoming the commodity initial-access market for ransomware, with leaked credential lists recurring across Pulse Secure and Fortinet products for years.