Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Massive Credential Theft Targets FortiGate Firewalls Worldwide

Massive Credential Theft Targets FortiGate Firewalls Worldwide

Posted on June 23, 2026 By CWS

A significant credential theft operation, dubbed FortiBleed, has targeted over 430,000 FortiGate firewalls globally. The operation, believed to be orchestrated by a financially-motivated, Russian-speaking initial access broker, has led to the harvesting of more than 110 million credentials since its inception in February 2026.

How the FortiBleed Operation Works

FortiBleed employs a variety of techniques to compromise FortiGate firewalls. The operation starts by identifying vulnerable systems using tools like Masscan and Shodan. Once located, attackers use a custom utility called FortiProbe-fast to filter these systems and categorize them by region.

Subsequently, the attackers breach these devices through credential stuffing and dictionary attacks, deploying a tool named “forticheck” that specifically targets administrative panels and SSL-VPN portals. Upon gaining access, they utilize a Golang-based tool, FortigateSniffer, to capture authentication traffic, exploiting the FortiOS diagnostic command for passive monitoring.

Targets and Tools

The campaign has focused primarily on Small and Medium Businesses (SMBs) with fewer than 200 employees, particularly in the United States and India. The IT services sector is notably at risk, providing potential pathways into customer environments through compromised service providers.

FortiBleed’s toolset includes the use of open-source platforms like CyberStrike and CyberStrikeAI, assisting in parts of the operation workflow. The campaign also employs automated brute-forcing, targeting a range of devices beyond Fortinet, including Synology NAS and Citrix SSL-VPNs.

Implications and Future Outlook

The operation involves executing up to 659 credential-harvesting pipelines, with attackers reportedly cracking password hashes using tools like Hashmat and Hashtopolis. A Telegram bot named HASHBOT orchestrates these efforts, facilitating lateral movement and Active Directory enumeration.

Reports indicate that the group ranks targets based on their economic value, allocating resources for exploitation accordingly. The operation is restricted to specific IP ranges and operates within defined time frames, indicating a highly organized attack structure.

The discovery of repeated username and password pairs across numerous IP addresses suggests the potential use of these credentials as backdoor entry points by the attackers. Furthermore, access to thousands of Fortinet devices has been advertised on cybercriminal forums, potentially linked to the FortiBleed breach.

The implications of this breach are profound, highlighting the necessity for enhanced cybersecurity measures and vigilant monitoring of network vulnerabilities. Organizations are advised to fortify their defenses and stay informed about evolving threats to mitigate potential risks.

The Hacker News Tags:credential theft, cyber threat, Cybersecurity, data breach, data protection, firewall security, FortiBleed, Fortigate, Fortinet, global cyber attack, Hacking, IT security, network security, network vulnerability, SMB security

Post navigation

Previous Post: Global Call for Cybersecurity Grants by Internet Society
Next Post: AWS Highlights Risks of Unmonitored Outbound Cloud Traffic

Related Posts

AI Coding Tool Flaw Exposes Developers to Code Exploits AI Coding Tool Flaw Exposes Developers to Code Exploits The Hacker News
Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide The Hacker News
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs The Hacker News
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks The Hacker News
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution The Hacker News
CISA Highlights Exploited Vulnerabilities in Key Software CISA Highlights Exploited Vulnerabilities in Key Software The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Levi Strauss Faces Cyber Intrusion via Social Engineering
  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Levi Strauss Faces Cyber Intrusion via Social Engineering
  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark