Last Update: 08/01/2026 at 1:00 PM EST

Fortinet Credential Leak Fallout

Coverage from BleepingComputer, Security Affairs, and others

Articles

8

Active Days

94

The Topic

Fortinet Credential Leak Fallout topic image

Fortinet VPN and firewall credentials were exposed at large scale, affecting tens of thousands of internet-facing devices and prompting government advisories, vendor warnings, and urgent password-reset guidance. The reporting also points to access brokering and credential cracking as part of the same compromise pattern.

First Article: 03/30/26

Latest Article: 07/01/26

Summary

  • Large credential exposure remains the dominant pattern, with reports converging on roughly 74,000 to 75,000 Fortinet devices and firewall URLs.
  • The exposed data includes usernames, email addresses, and passwords tied to FortiGate SSL VPN and firewall access, making the material immediately usable for intrusion.
  • Researchers and agencies link the leak to offline hash cracking, brute-force testing, and broader access-brokering activity rather than a single isolated breach.
  • Government and security responses are consistent: reset VPN and admin passwords, enable phishing-resistant MFA, review logs, and remove public access to management interfaces.
  • The same dataset is described as spanning many countries and organizations, including major companies and public-sector targets, which broadens its operational impact.
  • Fortinet devices remain a recurring exposure point because public management interfaces, stored credentials, and VPN access are all involved in the same risk surface.

History

This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.

Featured

Timeline: 94 Days

Mar 29Apr 19May 3May 24Jun 7Jun 28

Additional Articles

⭐⭐⭐⭐⭐

Security Affairs / Pierluigi Paganini06-18-2026
Hudson Rock and Kevin Beaumont, building on Bob Diachenko's findings, published guidance after a Fortinet VPN credential dataset exposed tens of thousands of internet-facing devices.
Security Affairs / Pierluigi Paganini06-24-2026
In June 2026, researcher Volodymyr Bob Diachenko uncovered FortiBleed, a leaked credential set exposing valid Fortinet firewall logins worldwide via an access-brokering vendor.
Business Insurance06-18-2026
Hudson Rock reported a Fortinet firewall and VPN credential theft campaign in more than 15 countries, involving large-scale device compromises and potential intrusions at companies and agencies.

⭐⭐⭐

Morocco World News / Asmae Daoudi06-20-2026
DGSSI warned on June 18 that FortiBleed exposed administrator credentials for Fortinet FortiGate and SSL VPN devices impacting Morocco and tens of thousands of systems globally.

⭐️⭐️

BleepingComputer / Sergiu Gatlan03-29-2026
Defused says attackers began exploiting CVE-2026-21643 in Fortinet FortiClient EMS, with CISA not yet listing it, while scans show thousands of exposed EMS interfaces.