Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Massive Credential Theft Targets FortiGate Firewalls Worldwide

Massive Credential Theft Targets FortiGate Firewalls Worldwide

Posted on June 23, 2026 By CWS

A significant credential theft operation, dubbed FortiBleed, has targeted over 430,000 FortiGate firewalls globally. The operation, believed to be orchestrated by a financially-motivated, Russian-speaking initial access broker, has led to the harvesting of more than 110 million credentials since its inception in February 2026.

How the FortiBleed Operation Works

FortiBleed employs a variety of techniques to compromise FortiGate firewalls. The operation starts by identifying vulnerable systems using tools like Masscan and Shodan. Once located, attackers use a custom utility called FortiProbe-fast to filter these systems and categorize them by region.

Subsequently, the attackers breach these devices through credential stuffing and dictionary attacks, deploying a tool named “forticheck” that specifically targets administrative panels and SSL-VPN portals. Upon gaining access, they utilize a Golang-based tool, FortigateSniffer, to capture authentication traffic, exploiting the FortiOS diagnostic command for passive monitoring.

Targets and Tools

The campaign has focused primarily on Small and Medium Businesses (SMBs) with fewer than 200 employees, particularly in the United States and India. The IT services sector is notably at risk, providing potential pathways into customer environments through compromised service providers.

FortiBleed’s toolset includes the use of open-source platforms like CyberStrike and CyberStrikeAI, assisting in parts of the operation workflow. The campaign also employs automated brute-forcing, targeting a range of devices beyond Fortinet, including Synology NAS and Citrix SSL-VPNs.

Implications and Future Outlook

The operation involves executing up to 659 credential-harvesting pipelines, with attackers reportedly cracking password hashes using tools like Hashmat and Hashtopolis. A Telegram bot named HASHBOT orchestrates these efforts, facilitating lateral movement and Active Directory enumeration.

Reports indicate that the group ranks targets based on their economic value, allocating resources for exploitation accordingly. The operation is restricted to specific IP ranges and operates within defined time frames, indicating a highly organized attack structure.

The discovery of repeated username and password pairs across numerous IP addresses suggests the potential use of these credentials as backdoor entry points by the attackers. Furthermore, access to thousands of Fortinet devices has been advertised on cybercriminal forums, potentially linked to the FortiBleed breach.

The implications of this breach are profound, highlighting the necessity for enhanced cybersecurity measures and vigilant monitoring of network vulnerabilities. Organizations are advised to fortify their defenses and stay informed about evolving threats to mitigate potential risks.

The Hacker News Tags:credential theft, cyber threat, Cybersecurity, data breach, data protection, firewall security, FortiBleed, Fortigate, Fortinet, global cyber attack, Hacking, IT security, network security, network vulnerability, SMB security

Post navigation

Previous Post: Global Call for Cybersecurity Grants by Internet Society
Next Post: AWS Highlights Risks of Unmonitored Outbound Cloud Traffic

Related Posts

Identity Posture: A Key Factor in Cyber Insurance 2026 Identity Posture: A Key Factor in Cyber Insurance 2026 The Hacker News
Supply Chain Attack Targets TanStack and AI Packages Supply Chain Attack Targets TanStack and AI Packages The Hacker News
Microsoft Unveils Tool to Detect AI Model Backdoors Microsoft Unveils Tool to Detect AI Model Backdoors The Hacker News
New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack The Hacker News
Policy, Isolation, and Data Controls That Actually Work Policy, Isolation, and Data Controls That Actually Work The Hacker News
eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised
  • Trump Boosts Post-Quantum Cryptography Efforts with New Order

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised
  • Trump Boosts Post-Quantum Cryptography Efforts with New Order

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark