FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest

Researchers attribute the long-running operation to a financially motivated IAB, with credential lists feeding brute-force runs against exposed FortiGate appliances since February.

ThreatVectr Newsdesk· 2 min read
FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest
Share

A credential-harvesting campaign tracked as FortiBleed has hit more than 430,000 FortiGate firewalls since February 2026, and researchers assess with medium confidence that the operator is a Russian-speaking initial access broker working for profit rather than a state sponsor.

The distinction matters.

IAB activity tends to end in a marketplace listing — credentials, VPN access, or a foothold sold on to ransomware affiliates. That puts FortiBleed in capability terms closer to the access-broker clusters some vendors lump under Storm- designations than to espionage crews like Sandworm or APT28, even if the victim overlap may eventually look similar.

The operational pattern is unglamorous and effective. The actor pulls together credential lists from prior breaches and infostealer logs, fingerprints internet-exposed FortiGate management interfaces and SSL-VPN portals, then runs brute-force and credential-stuffing attempts against anything that answers. Successful logins get a bespoke post-exploitation toolkit dropped behind them, used to persist on the device and pivot inward.

That TTP chain — stealer-log aggregation feeding edge-device password spraying — overlaps heavily with access-broker tradecraft observed against Cisco ASA, SonicWall, and Ivanti Connect Secure boxes through 2024 and 2025. It is not novel. It is just well-tuned to a device class that sits on the perimeter, often without MFA on the local admin account, and frequently behind on firmware.

430,000 appliances is a large number. It is worth reading as the population the actor probed or touched, not the count of compromised devices. A successful credential validation against an exposed SSL-VPN is a much smaller subset, and the figure of 110 million credentials being circulated in connection with the campaign appears to describe the input wordlists rather than the output of confirmed valid pairs.

Fortinet has not, at the time of writing, published an advisory linking specific CVEs to this activity, and the reporting so far points to credential abuse rather than zero-day exploitation. Defenders should treat it as an authentication problem first. Administrators running FortiGate appliances with internet-reachable management or VPN services should pull authentication logs going back to February, look for high-volume failed logins followed by a single success from the same ASN, and check for unexpected admin accounts or configuration changes.

MFA on every administrative and VPN account. Geo-fencing where the business allows it. Rotation of any credential that has ever appeared in a stealer log dump.

Attribution to a single Russian-speaking IAB rests on language artifacts and infrastructure overlap, which is thin ground on its own. Until a vendor publishes named-cluster analysis with infrastructure indicators, treat the actor profile as provisional and the TTPs as the actionable part.

© 2026 Threat Vectr