FortiBleed: What Businesses Need to Know About the Fortinet Credential Exposure Campaign

July 28, 2026

figure

Firewalls are designed to keep unauthorized users out of a business’s network. But when an attacker obtains a valid username and password, they may be able to access the same systems trusted employees and administrators use every day.

That is the concern surrounding FortiBleed, a large-scale credential exposure campaign involving internet-facing Fortinet FortiGate firewalls and VPN gateways.

Fortinet has said the activity is not connected to a new software vulnerability. Its initial analysis points instead to reused credentials, brute-force activity, weak password practices, and accounts that were not protected by multi-factor authentication, or MFA.[1]

For businesses using Fortinet devices, the immediate priority is to understand whether credentials or systems may have been exposed and take practical steps to reduce further risk.

What Is FortiBleed?

FortiBleed is the name researchers have given to a campaign involving exposed administrative and VPN credentials connected to Fortinet devices.

In June 2026, researchers reported finding a database containing credentials associated with organizations in 194 countries. The Cybersecurity and Infrastructure Security Agency, or CISA, reported that the leaked credentials were connected to approximately 74,000 Fortinet devices.[2]

That figure does not necessarily mean that 74,000 organizations experienced a broader network compromise. It does, however, show the potential scale of the exposure.

The database reportedly included usernames, email addresses, and passwords associated with more than 21,000 domains. Businesses, government entities, and organizations across several industries appeared in the data.[3]

FortiBleed is also different from many high-profile cyber incidents. It is not believed to involve a newly discovered zero-day vulnerability that can be addressed with a single new patch. Fortinet has stated that the activity is not connected to a recent security advisory or newly identified Fortinet vulnerability.[1]

How Did This Happen?

The complete history of every credential in the database is not known. Current reporting suggests that attackers may have used several methods to collect or test credentials, including:

  1. Credentials obtained through earlier security incidents
  2. Brute-force and dictionary attacks
  3. Passwords exposed in previous data breaches
  4. Weak or reused administrative passwords
  5. Internet-facing management and VPN portals without MFA
  6. Credentials recovered from configuration files or password hashes

The UK National Cyber Security Centre, or NCSC, reported that the exposed database followed brute-force, dictionary, and credential-stuffing attempts against internet-facing FortiGate and VPN portals.[4]

Sophos also reported evidence involving exported configuration files and password-hash cracking. However, the company noted that public information about how every credential was originally obtained remains limited.[3]

This distinction matters. When an attacker uses a working administrator or VPN password, the activity may initially look like a legitimate login. That can make unauthorized access harder to identify than a traditional attempt to exploit a software flaw.

Why This Matters

Fortinet firewalls and VPN gateways often sit at the edge of an organization’s network. They may control remote access, administrative functions, and connections to important internal systems.

An attacker who gains administrative access may be able to:

  1. Change firewall or VPN settings
  2. Create unauthorized accounts
  3. Establish persistent remote access
  4. Disable or weaken security controls
  5. Access connected authentication systems
  6. Use the device to reach other parts of the network
  7. Attempt to steal information or deploy ransomware

An exposed credential does not automatically mean the entire network was compromised. Still, credentials for a perimeter security device should be treated seriously and reviewed promptly.

Fortinet recommends checking device configurations for unauthorized changes, reviewing administrator accounts, and examining logs for unusual access or signs that an attacker attempted to move beyond the device.[1]

Current Situation

Government agencies, Fortinet, and cybersecurity firms have advised organizations to review their environments and strengthen affected devices.

CISA issued an alert following reports that credentials associated with approximately 74,000 Fortinet devices had been exposed.[2] The NCSC also advised organizations using Fortinet firewalls and VPN gateways to look for unauthorized accounts, unusual log activity, and other possible signs of compromise.[4]

Fortinet has said it identified systems that may have been affected and is contacting customers as part of its response.[1]

Because the available information may continue to change, businesses should follow current guidance from Fortinet and relevant government cybersecurity authorities.

Recommended Actions

Businesses should work with their internal cybersecurity team, managed service provider, incident response partner, or another qualified technology professional before making significant changes to critical systems.

The following steps can provide a starting point.

1. End active sessions and reset credentials

Terminate active administrator and VPN sessions. Reset administrative and VPN passwords, with particular attention to internet-facing systems.

Use strong, unique passwords that are not shared with other accounts or platforms.

2. Review connected accounts

Identify whether the Fortinet device connects to Active Directory, LDAP, RADIUS, APIs, service accounts, or other authentication services.

When exposure is suspected, credentials connected to those systems may also need to be reviewed and reset.[1][3]

3. Enable multi-factor authentication

Require MFA for administrator, VPN, remote-access, and other privileged accounts.

Fortinet recommends MFA for administrator and VPN users. The NCSC also recommends MFA for VPN and device-management access.[1][4]

MFA adds another layer of verification, which can help prevent a stolen password from being enough to access a system.

4. Limit administrative access

Avoid making device-management portals directly available from the public internet whenever possible.

Restrict access to trusted internal networks, approved devices, secured administrative systems, or VPN connections protected by MFA.

5. Review accounts and configurations

Check for activity that does not match approved business or technology changes, including:

  • Administrator or VPN accounts no one recognizes
  • Unexpected password resets
  • Changes to firewall or VPN rules
  • New remote-access settings
  • Other unapproved configuration changes

When possible, compare the current configuration with a known and trusted version.

6. Review logs and network activity

Look for unusual administrator logins, unfamiliar IP addresses or locations, configuration exports, unexpected account activity, and unexplained system changes.

The review should not stop at the Fortinet device. Connected systems may also need to be checked for signs of unauthorized access.

7. Update and harden affected devices

FortiBleed is not considered a new software vulnerability, but supported and current software still matters.

Organizations should follow Fortinet’s recommended upgrade path and confirm that their devices are running supported software. Fortinet also recommends versions that use stronger PBKDF2 password hashing for administrator credentials.[1]

Devices that are no longer supported should be evaluated for replacement or removal from service.

8. Investigate signs of compromise

Resetting a password may not resolve the issue when an attacker has already created another account, changed a configuration, or established another way to access the network.

Fortinet advises treating a device as compromised when unauthorized configuration changes or other indicators are found.[1] The NCSC also recommends isolating affected devices, preserving relevant evidence, and investigating other systems that may have been accessible from the device.[4]

Organizations should follow their incident response plan and involve appropriate cybersecurity, legal, and risk-management professionals.

The Bigger Picture

FortiBleed highlights a broader reality about cyber risk. Attackers do not always need a sophisticated new vulnerability to gain access.

A reused password, an exposed management portal, or an account without MFA may provide another path into an organization.

Patching remains an important part of cybersecurity, but it is not the full picture. Businesses also need to manage identities, limit privileged access, secure remote connections, monitor unusual activity, and maintain strong password practices.

The FortiBleed campaign gives organizations an opportunity to ask a few practical questions:

  • Are administrative portals exposed to the public internet?
  • Do all privileged accounts require MFA?
  • Are passwords unique across systems?
  • Would the organization recognize an unexpected configuration export?
  • Does the team know what to do when suspicious access is detected?

Clear answers can help identify weaknesses before they contribute to a larger incident.

Where Cyber Insurance Fits

Strong cybersecurity controls can reduce risk, but they cannot eliminate it completely.

Cyber insurance may help support an organization’s response to a covered incident through resources such as breach counsel, digital forensics, incident response support, crisis communications, data recovery, and certain business interruption coverage.

Coverage depends on the specific policy terms, carrier, jurisdiction, cause of loss, and the organization’s risk profile. Businesses should review their coverage and incident response plans before an event occurs.

Insurers may also consider controls such as MFA, secure remote access, privileged-account management, supported software, and timely security updates when evaluating cyber risk.

Cyber insurance does not replace strong security practices. It can support a broader plan for preparing for, responding to, and recovering from an incident.

To discuss how cyber insurance may fit into your broader risk-management strategy, connect with a Patriot Growth Insurance Services expert.

Final Thoughts

FortiBleed is a useful reminder that cybersecurity is not only about patching software. Businesses also need to understand who has access to critical systems, how credentials are managed, and whether unusual activity would be detected quickly.

Organizations using Fortinet FortiGate firewalls or VPN gateways should review current vendor guidance, reset relevant credentials, confirm that MFA is in place, limit administrative access, and investigate potential signs of unauthorized activity.

These steps can help businesses better understand their exposure and make informed decisions about what comes next.

To discuss how cyber insurance fits into your broader risk-management strategy, connect with a local Patriot expert.

Sources

[1] Fortinet: “Analysis of Reported Credential Compromise of FortiGate Devices,” June 19, 2026.

[2] Cybersecurity and Infrastructure Security Agency: “CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure,” June 18, 2026.

[3] Sophos: “Fortinet ‘FortiBleed’ Credential Exposure and Sophos VPN Bruteforcing Campaign,” updated June 23, 2026.

[4] UK National Cyber Security Centre: “Advice Following Global Targeting of Fortinet Firewalls and VPN Gateways,” June 18, 2026.

Share this post:
Facebook Icon X Icon LinkedIn Icon