FortiBleed: What 86,000 Compromised Firewalls Reveal About Security Basics
The world's leading firewall vendor, trusted by over 900,000 customers, has had more than 75,000 devices compromised with nothing more than valid logins. Here's what FortiBleed reveals about security fundamentals, no matter what vendor sits at your perimeter.
Risk Level
Read Time
“Ok, so what actually happened?”
For at least five months, an organized cyber threat operation has been harvesting valid administrative credentials for Fortinet firewalls. The campaign, now named FortiBleed, came to light in June 2026 when researchers discovered the attackers’ own server accidentally left exposed. On it, researchers found a database of verified login credentials for as many as 86,000 devices across 194 countries.
“Ok, but what’s in it for me?”
FortiBleed didn’t stop at stolen passwords. SOCRadar researchers have identified two main ransomware groups at play, INC and Lynx. One of these operators was recently found actively involved in a ransomware group's negotiation panels. At least a dozen recent ransomware attacks have already been linked to FortiBleed credential databases.
Here's the real takeaway for organizations: In a world where so many data breaches are tied to unpatched vulnerabilities, FortiBleed is a reminder that some of the most disruptive attacks don't necessarily rely on sophisticated exploits. They rely on weak security fundamentals.
“How did they get in?”
Fortinet devices store administrator credentials, including password hashes, in configuration files. Before the breach, Fortinet transitioned its config file encryption from Salted SHA-256 to a stronger algorithm called PBKDF2. A firmware update alone may not be enough. Older SHA-256 hashes can stay in place until each admin logs in again and rehashes the password. The FortiBleed hackers targeted devices that were never updated and still using the legacy encryption method.
By using AI-assisted tools, the hackers scanned for internet-facing firewalls with exposed ports. Then, they attempted credential-based access by brute forcing weak passwords and Single-Sign-on (SSO). With nothing more than consumer GPUs, they could run millions of SHA-256 guesses per second, cracking stored passwords at scale. Curious how fast your passwords could fail? Check out the 2026 Password Tables, to take a closer look at password strengths and how quickly modern GPUs can crack them.
“I use Fortinet firewalls, what should I do?”
First, it is imperative to harden your devices. In cybersecurity, the term “hardening” means implementing stricter security practices to lower the risk of unauthorized access. The Cybersecurity and Infrastructure Security Agency (CISA) urges Fortinet administrators to:
Ensure firewalls are not accessible from the public internet
Terminate all active VPN and administrative login sessions
Reset credentials
Confirm all firewalls have been updated from the legacy encryption algorithm to PBKDF2
Review logs for unusual or unauthorized access
“I don't use Fortinet, why should I care?”
FortiBleed isn’t just a Fortinet story. It’s a story about how simple oversights like weak passwords, delayed updates, and interfaces left open to the public can escalate into downtime, ransomware, and real financial damage. The FortiBleed attackers didn’t need to outsmart anyone's security. They just needed someone to overlook the basics. If you want to see where security gaps show up in your own IT network, Hive Systems can help through penetration testing.
Test your defenses with our penetration testing services.
Follow us - stay ahead.
It’s finally here! Hive Systems’ famous Password Table for 2026 shows how fast hackers can crack your passwords with today’s hardware. Whether you’re in security or just online, you NEED to see this year’s updates. Find out if your passwords are still safe or if it’s time for a change while downloading your copy.