A hacker has posted a list of usernames, passwords, IP addresses and SSH keys of 900+ Pulse Secure VPN enterprise servers on a Russian-speaking hacker forum
EXCLUSIVE: The list has been shared on a Russian-speaking hacker forum frequented by multiple ransomware gangs.
Context & Ripple Effects
This dump is not an isolated incident but the latest entry in a pattern of VPN credential leaks that has been building since at least the 2019 wave of attacks on Pulse Secure and Fortinet VPN appliances right after critical flaws went public. The forum in question matters because it is frequented by multiple ransomware gangs, turning a raw credential list into ready-made initial access for ransomware operators.
The same playbook recurs across vendors and years: hackers later leaked roughly 500K Fortinet VPN logins with some confirmed valid, and an even larger collection of FortiGate credentials surfaced covering firewall URLs worldwide — evidence that VPN appliance credentials are treated as a standing commodity in criminal markets.
First-order effects
- Enterprises running the 900+ listed Pulse Secure servers face immediate risk of unauthorized remote access, since usernames, passwords, IPs and SSH keys are now public to ransomware-affiliated buyers.
- Pulse Secure's incident response teams must treat every server on the list as compromised until credentials and keys are rotated.
Second-order effects
- Ransomware gangs gain a low-cost entry path into corporate networks, bypassing phishing entirely by logging in with stolen VPN credentials.
- Security teams will likely accelerate moves toward credential-rotation policies and multi-factor authentication on VPN gateways, pressuring vendors to harden default configurations.
Third-order effects
- If the pattern holds — from the Pulse Secure dump through repeated Fortinet leaks — VPN appliances consolidate as the preferred initial-access vector for ransomware, pushing enterprises to treat edge-device credential hygiene as a board-level control rather than an IT task.
- Law enforcement's seizure of criminal-market VPN infrastructure shows authorities responding to this ecosystem, but the recurring vendor-side leaks suggest regulation of enterprise appliance security practices may follow.
The trend: Enterprise VPN appliances are becoming the commodity initial-access market for ransomware, with leaked credential lists recurring across Pulse Secure and Fortinet products for years.