Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Massive Credential Theft Targets FortiGate Firewalls Worldwide

Massive Credential Theft Targets FortiGate Firewalls Worldwide

Posted on June 23, 2026 By CWS

A significant credential theft operation, dubbed FortiBleed, has targeted over 430,000 FortiGate firewalls globally. The operation, believed to be orchestrated by a financially-motivated, Russian-speaking initial access broker, has led to the harvesting of more than 110 million credentials since its inception in February 2026.

How the FortiBleed Operation Works

FortiBleed employs a variety of techniques to compromise FortiGate firewalls. The operation starts by identifying vulnerable systems using tools like Masscan and Shodan. Once located, attackers use a custom utility called FortiProbe-fast to filter these systems and categorize them by region.

Subsequently, the attackers breach these devices through credential stuffing and dictionary attacks, deploying a tool named “forticheck” that specifically targets administrative panels and SSL-VPN portals. Upon gaining access, they utilize a Golang-based tool, FortigateSniffer, to capture authentication traffic, exploiting the FortiOS diagnostic command for passive monitoring.

Targets and Tools

The campaign has focused primarily on Small and Medium Businesses (SMBs) with fewer than 200 employees, particularly in the United States and India. The IT services sector is notably at risk, providing potential pathways into customer environments through compromised service providers.

FortiBleed’s toolset includes the use of open-source platforms like CyberStrike and CyberStrikeAI, assisting in parts of the operation workflow. The campaign also employs automated brute-forcing, targeting a range of devices beyond Fortinet, including Synology NAS and Citrix SSL-VPNs.

Implications and Future Outlook

The operation involves executing up to 659 credential-harvesting pipelines, with attackers reportedly cracking password hashes using tools like Hashmat and Hashtopolis. A Telegram bot named HASHBOT orchestrates these efforts, facilitating lateral movement and Active Directory enumeration.

Reports indicate that the group ranks targets based on their economic value, allocating resources for exploitation accordingly. The operation is restricted to specific IP ranges and operates within defined time frames, indicating a highly organized attack structure.

The discovery of repeated username and password pairs across numerous IP addresses suggests the potential use of these credentials as backdoor entry points by the attackers. Furthermore, access to thousands of Fortinet devices has been advertised on cybercriminal forums, potentially linked to the FortiBleed breach.

The implications of this breach are profound, highlighting the necessity for enhanced cybersecurity measures and vigilant monitoring of network vulnerabilities. Organizations are advised to fortify their defenses and stay informed about evolving threats to mitigate potential risks.

The Hacker News Tags:credential theft, cyber threat, Cybersecurity, data breach, data protection, firewall security, FortiBleed, Fortigate, Fortinet, global cyber attack, Hacking, IT security, network security, network vulnerability, SMB security

Post navigation

Previous Post: Global Call for Cybersecurity Grants by Internet Society
Next Post: AWS Highlights Risks of Unmonitored Outbound Cloud Traffic

Related Posts

Organizations Struggle with Cyberattack Preparedness Organizations Struggle with Cyberattack Preparedness The Hacker News
AI Coding Tools Trigger Security Alerts in Endpoint Systems AI Coding Tools Trigger Security Alerts in Endpoint Systems The Hacker News
Cybersecurity Threats: Game Cheat Spyware and More Cybersecurity Threats: Game Cheat Spyware and More The Hacker News
Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network The Hacker News
Azure Cosmos DB Vulnerability Could Access Databases Azure Cosmos DB Vulnerability Could Access Databases The Hacker News
Critical Unisoc VoLTE Exploit Grants Kernel Access Critical Unisoc VoLTE Exploit Grants Kernel Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F5 BIG-IP Zero-Day Vulnerability Exploited
  • Next.js Vulnerability Allows Server Code Execution via SVG
  • Check Point Issues Critical Patch for Zero-Day Vulnerability
  • FBI Data Compromised by Cyber Group ShinyHunters
  • FBI Probes Alleged ShinyHunters Data Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F5 BIG-IP Zero-Day Vulnerability Exploited
  • Next.js Vulnerability Allows Server Code Execution via SVG
  • Check Point Issues Critical Patch for Zero-Day Vulnerability
  • FBI Data Compromised by Cyber Group ShinyHunters
  • FBI Probes Alleged ShinyHunters Data Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark