2 min read

FortiBleed Campaign Exposes 430,000 Fortinet Firewalls to Ransomware Operators Worldwide

The FortiBleed campaign has emerged as one of the most devastating credential theft operations in recent memory, with security researchers confirming that threat actors have systematically harvested administrator credentials from an estimated 430,000 FortiGate firewall devices spanning 194 countries. The campaign, first identified in mid-June 2026, has now been definitively linked to the INC Ransom and Lynx ransomware operations, raising alarm bells across the global cybersecurity community.

The Anatomy of FortiBleed

At its core, FortiBleed exploits a fundamental weakness in how Fortinet devices have historically stored administrator credentials. Prior to FortiOS versions 7.2.11, 7.4.8, and 7.6.1, FortiGate configuration files stored admin passwords using SHA-256 with salt hashing mechanisms. While Fortinet introduced more robust PBKDF2-based password hashing in those later versions, the migration path left a critical gap: existing administrator passwords remained stored as SHA-256 hashes until the administrator successfully logged in after the upgrade.

This meant that organizations that upgraded their firmware but did not force credential rotations were left with crackable hashes sitting in their configuration files. Threat actors exploited this by extracting configuration files from internet-facing FortiGate devices and systematically cracking the stored credential hashes offline.

Staggering Scale of Compromise

The numbers are sobering. Recorded Future confirmed that verified working administrator credentials for between 30,000 and 75,000 unique devices had been extracted, with the broader campaign targeting roughly 86,644 unique devices. BitSight and Arctic Wolf corroborated these findings, noting that the compromised devices represent approximately half of all internet-facing Fortinet firewalls globally.

More alarming still, the campaign is assessed to have gathered over 110 million credentials in total, making it one of the largest single-source credential harvesting operations ever documented.

The Ransomware Pipeline

What elevates FortiBleed from a credential theft campaign to a full-blown crisis is its direct connection to ransomware operations. BleepingComputer reported that an operator with access to FortiBleed infrastructure was found logged into both INC Ransom and Lynx negotiation panels. Victim organizations listed by INC Ransom showed significant overlap with data harvested during the FortiBleed campaign.

At least 12 confirmed ransomware deployments have been traced back to FortiBleed access, resulting in hundreds of encrypted endpoints across affected organizations. The stolen credentials served as the initial access vector, allowing ransomware operators to bypass perimeter defenses entirely.

Emergency Response and Mitigation

The Cybersecurity and Infrastructure Security Agency issued an urgent advisory on June 18, 2026, calling on organizations to immediately harden their Fortinet devices. CISA recommended rotating all administrator credentials, upgrading to FortiOS versions that support PBKDF2 hashing, and auditing configuration file access logs for unauthorized retrievals.

Fortinet acknowledged the campaign in a blog post from its Product Security Incident Response Team, confirming that the vulnerability stemmed from legacy credential storage mechanisms rather than a new software flaw. The company urged customers to ensure that all administrator accounts have logged in at least once after upgrading to trigger the migration to stronger hashing.

For organizations that cannot confirm whether their credentials were compromised, security firms recommend treating all FortiGate administrator accounts as potentially exposed and implementing full credential rotation alongside multi-factor authentication enforcement.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.