Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Massive Credential Theft Targets FortiGate Firewalls Worldwide

Massive Credential Theft Targets FortiGate Firewalls Worldwide

Posted on June 23, 2026 By CWS

A significant credential theft operation, dubbed FortiBleed, has targeted over 430,000 FortiGate firewalls globally. The operation, believed to be orchestrated by a financially-motivated, Russian-speaking initial access broker, has led to the harvesting of more than 110 million credentials since its inception in February 2026.

How the FortiBleed Operation Works

FortiBleed employs a variety of techniques to compromise FortiGate firewalls. The operation starts by identifying vulnerable systems using tools like Masscan and Shodan. Once located, attackers use a custom utility called FortiProbe-fast to filter these systems and categorize them by region.

Subsequently, the attackers breach these devices through credential stuffing and dictionary attacks, deploying a tool named “forticheck” that specifically targets administrative panels and SSL-VPN portals. Upon gaining access, they utilize a Golang-based tool, FortigateSniffer, to capture authentication traffic, exploiting the FortiOS diagnostic command for passive monitoring.

Targets and Tools

The campaign has focused primarily on Small and Medium Businesses (SMBs) with fewer than 200 employees, particularly in the United States and India. The IT services sector is notably at risk, providing potential pathways into customer environments through compromised service providers.

FortiBleed’s toolset includes the use of open-source platforms like CyberStrike and CyberStrikeAI, assisting in parts of the operation workflow. The campaign also employs automated brute-forcing, targeting a range of devices beyond Fortinet, including Synology NAS and Citrix SSL-VPNs.

Implications and Future Outlook

The operation involves executing up to 659 credential-harvesting pipelines, with attackers reportedly cracking password hashes using tools like Hashmat and Hashtopolis. A Telegram bot named HASHBOT orchestrates these efforts, facilitating lateral movement and Active Directory enumeration.

Reports indicate that the group ranks targets based on their economic value, allocating resources for exploitation accordingly. The operation is restricted to specific IP ranges and operates within defined time frames, indicating a highly organized attack structure.

The discovery of repeated username and password pairs across numerous IP addresses suggests the potential use of these credentials as backdoor entry points by the attackers. Furthermore, access to thousands of Fortinet devices has been advertised on cybercriminal forums, potentially linked to the FortiBleed breach.

The implications of this breach are profound, highlighting the necessity for enhanced cybersecurity measures and vigilant monitoring of network vulnerabilities. Organizations are advised to fortify their defenses and stay informed about evolving threats to mitigate potential risks.

The Hacker News Tags:credential theft, cyber threat, Cybersecurity, data breach, data protection, firewall security, FortiBleed, Fortigate, Fortinet, global cyber attack, Hacking, IT security, network security, network vulnerability, SMB security

Post navigation

Previous Post: Global Call for Cybersecurity Grants by Internet Society
Next Post: AWS Highlights Risks of Unmonitored Outbound Cloud Traffic

Related Posts

Malicious Go, npm Packages Deliver Cross-Platform Malware, Trigger Remote Data Wipes Malicious Go, npm Packages Deliver Cross-Platform Malware, Trigger Remote Data Wipes The Hacker News
Microsoft Addresses 206 Security Vulnerabilities, Including Zero-Days Microsoft Addresses 206 Security Vulnerabilities, Including Zero-Days The Hacker News
WordPress Plugins Compromised: Hidden Backdoors Revealed WordPress Plugins Compromised: Hidden Backdoors Revealed The Hacker News
Anthropic’s Claude Code Leak: Human Error Leads to Source Code Exposure Anthropic’s Claude Code Leak: Human Error Leads to Source Code Exposure The Hacker News
6M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More $176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More The Hacker News
Google Reports Exploitation of Qualcomm Android Vulnerability Google Reports Exploitation of Qualcomm Android Vulnerability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled
  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled
  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark