News Article · Jun 18, 2026 at 1:39 PM
2 min read 0
Member
FortiBleed Leak Exposes 74,000 Fortinet Firewall Credentials in Plaintext
Security #cybersecurity #Fortinet #FortiBleed #credential leak #firewall #VPN

FortiBleed Leak Exposes 74,000 Fortinet Firewall Credentials in Plaintext

A cache of 74,000 Fortinet firewall credentials was leaked online, exposing plaintext usernames and passwords for devices worldwide. The data, dubbed FortiBleed, was discovered by security researcher Volodymyr Diachenko.

Listen to this article 3 min

Security researchers have uncovered a massive cache of stolen credentials for Fortinet firewalls, exposing login details for tens of thousands of organizations worldwide. The dataset, dubbed FortiBleed, contains plaintext usernames, emails, and passwords for 73,932 unique Fortinet FortiGate firewall and VPN devices across 194 countries.

The data was accidentally exposed by a Russian-speaking cybercriminal group on a server, along with other artifacts and tools. Security researcher Volodymyr “Bob” Diachenko noticed the exposure and raised the alarm last weekend. Other researchers have since analyzed the dataset, which touches more than 21,000 domains.

How the Attack Worked

The attackers did not exploit a zero-day vulnerability. Instead, they used old passwords obtained from previous breaches or brute-force attacks against Fortinet devices that had not been patched or had weak credentials. The stolen configuration files contained plaintext credentials, making them immediately usable for further attacks.

  • 73,932 unique Fortinet FortiGate firewall and VPN devices were compromised.
  • The data spans 194 countries and affects more than 21,000 domains.
  • Credentials were stored in plaintext within configuration files, a known security risk.
  • The leak was accidental, caused by the group's own server misconfiguration.
  • Researchers estimate that around 75,000 users may have been affected.

Implications for Organizations

The FortiBleed leak highlights a persistent problem: organizations failing to change default passwords or apply security patches. Fortinet has issued advisories in the past urging customers to rotate credentials and enable multi-factor authentication. However, many devices remain vulnerable due to poor security hygiene.

Organizations listed in the leak should immediately rotate all firewall and VPN credentials, audit their configurations for plaintext passwords, and enable multi-factor authentication. They should also check for signs of unauthorized access, as the exposed credentials could be used to pivot into internal networks.

Security researchers are working with affected organizations to mitigate the damage. The incident serves as a reminder that even sophisticated attacks often rely on basic security failures. Fortinet has not yet issued a formal statement on the FortiBleed leak, but customers are advised to follow best practices for device security.

Fact check

  • The dataset contains credentials for 73,932 unique Fortinet FortiGate firewall and VPN devices.

    reported · source

  • The data was accidentally exposed by a Russian-speaking cybercriminal group on a server.

    reported · source

  • The leak was discovered by security researcher Volodymyr 'Bob' Diachenko.

    reported · source

  • The attackers used old passwords obtained from previous breaches or brute-force attacks, not a zero-day vulnerability.

    reported · source

Source reporting (3)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 226 users online: 0 registered, 219 guests and 7 bots.

Most users ever online was 1,755 on 17 Jun 2026, 5:11 pm.

Bots: AhrefsBot Applebot Baiduspider Bingbot Facebook Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 359