CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

An update on FortiBleed - what’s happening with victim orgs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 583

As cited

Copy frozen at (site build).

ransomware

An update on FortiBleed - what’s happening with victim orgs

FortiBleed exposed Fortinet firewall administrator credentials at scale after an attacker gained access to tens of thousands of devices, exported configurations, and cracked password hashes using rented GPU compute resources. The attacker's infrastructure left evidence in an open directory, revealing that approximately 1,000 organizations were directly compromised, though credential theft occurred across tens of thousands of devices, with stolen FortiVPN credentials now being resold on underground forums. Many victim organizations show evidence of configuration exports in their logs over the past month from multiple IP addresses.

Why it matters: Fortinet firewall administrators and security teams managing Fortigate devices need to immediately review System event logs for unauthorized config exports, verify whether their devices were compromised, rotate administrative credentials, and investigate whether dormant backdoor accounts from prior ransomware campaigns are present in their infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

An update on FortiBleed - what’s happening with victim orgs

FortiBleed exposed Fortinet firewall administrator credentials at scale after an attacker gained access to tens of thousands of devices, exported configurations, and cracked password hashes using rented GPU compute resources. The attacker's infrastructure left evidence in an open directory, revealing that approximately 1,000 organizations were directly compromised, though credential theft occurred across tens of thousands of devices, with stolen FortiVPN credentials now being resold on underground forums. Many victim organizations show evidence of configuration exports in their logs over the past month from multiple IP addresses.

Why it matters: Fortinet firewall administrators and security teams managing Fortigate devices need to immediately review System event logs for unauthorized config exports, verify whether their devices were compromised, rotate administrative credentials, and investigate whether dormant backdoor accounts from prior ransomware campaigns are present in their infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

An update on FortiBleed - what’s happening with victim orgs

FortiBleed exposed Fortinet firewall administrator credentials at scale after an attacker gained access to tens of thousands of devices, exported configurations, and cracked password hashes using rented GPU compute resources. The attacker's infrastructure left evidence in an open directory, revealing that approximately 1,000 organizations were directly compromised, though credential theft occurred across tens of thousands of devices, with stolen FortiVPN credentials now being resold on underground forums. Many victim organizations show evidence of configuration exports in their logs over the past month from multiple IP addresses.

Why it matters: Fortinet firewall administrators and security teams managing Fortigate devices need to immediately review System event logs for unauthorized config exports, verify whether their devices were compromised, rotate administrative credentials, and investigate whether dormant backdoor accounts from prior ransomware campaigns are present in their infrastructure.

VendorsFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary