FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest

Researchers attribute the long-running operation to a financially motivated IAB, with credential lists feeding brute-force runs against exposed FortiGate appliances since February.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest
Share

Key points

  • A Russian-speaking initial access broker is assessed with medium confidence to be behind the FortiBleed credential-harvesting campaign.
  • More than 430,000 FortiGate firewalls have been targeted globally since February 2026.
  • The 110 million credential figure describes input wordlists, not confirmed valid pairs.
  • Fortinet has not published an advisory linking specific CVEs to this activity; treat it as an authentication problem.
  • MFA on every administrative and VPN account is the immediate defensive priority.

What is FortiBleed?

FortiBleed is a credential-harvesting campaign, active since February 2026, in which a financially motivated initial access broker (IAB, a threat actor who sells compromised access rather than exploiting it directly) probed more than 430,000 FortiGate firewalls worldwide. Researchers assess with medium confidence that the operator is Russian-speaking and working for profit, not a state sponsor.

That distinction matters. IAB activity tends to end in a marketplace listing: credentials or a foothold sold on to ransomware affiliates. That puts FortiBleed closer in capability terms to the access-broker clusters some vendors track under Storm- designations than to espionage crews like Sandworm or APT28, even if victim overlap may eventually look similar.

How does the campaign work?

The actor aggregates credential lists from prior breaches and infostealer logs, fingerprints internet-exposed FortiGate management interfaces and SSL-VPN portals, then runs brute-force and credential-stuffing attempts against anything that responds. Successful logins get a bespoke post-exploitation toolkit dropped, used to persist on the device and pivot inward.

That TTP chain overlaps heavily with access-broker tradecraft observed against Cisco ASA, SonicWall boxes, and Ivanti Connect Secure through 2024 and 2025. It's not novel. It's well-tuned to a device class that sits on the perimeter, often without MFA on the local admin account, and frequently behind on firmware. We first reported on this campaign on 18 June, when the exposed population stood at 75,000 firewalls; the figure has since grown nearly sixfold.

Should you worry about the 110 million credential figure?

430,000 appliances is a large number to read carefully. It's the population the actor probed or touched, not a count of compromised devices. The 110 million credential figure appears to describe the input wordlists, not confirmed valid pairs; a successful credential validation against an exposed SSL-VPN is a far smaller subset.

Fortinet hadn't, at the time of writing, published an advisory linking specific CVEs to this activity. Reporting points to credential abuse rather than zero-day exploitation.

What should defenders do?

Administrators running FortiGate appliances with internet-reachable management or VPN services should pull authentication logs back to February and look for high-volume failed logins followed by a single success from the same ASN, then check for unexpected admin accounts or configuration changes.

Beyond log review: MFA on every administrative and VPN account, geo-fencing where the business permits it, and rotation of any credential that has appeared in a stealer log dump.

How solid is the attribution?

Attribution to a single Russian-speaking IAB rests on language artifacts and overlapping infrastructure, which is thin ground. Until a vendor publishes named-cluster analysis with infrastructure indicators, treat the actor profile as provisional and the TTPs as the actionable part. Single-source attribution on campaigns this broad deserves skepticism; what's clear is the technique, not who's holding the keyboard.

© 2026 Threat Vectr