In June 2026, a massive credential leak dubbed “FortiBleed” was discovered targeting Fortinet’s FortiGate firewalls and SSL VPN appliances. Roughly 74,000 devices across 194 countries were affected, and it emerged that even fully patched devices remained exposed to credential abuse. The incident has drawn sharp attention as a new breed of cyberattack aimed at the “gatekeepers” of enterprise networks. Governments and security agencies worldwide — including Taiwan — have raised the alarm, urging organizations to change passwords, restrict access, and update to the latest firmware. This article explains what FortiBleed is, the scope of damage, the attackers’ methods, and the steps you need to take right now.
日本語記事はこちら
👉FortiBleedとは何か|世界194か国・7万4000台のFortiGateで認証情報流出
What Is FortiBleed? — The FortiGate Credential Leak Affecting 74,000 Devices
The “Keys” to Firewalls Leaked at Scale
According to CISA’s advisory, FortiBleed is not the result of a single zero-day vulnerability. Attackers compiled large volumes of credentials from previously leaked datasets and infostealer malware, then used clusters of up to 45 GPUs to crack password hashes offline.
BleepingComputer’s investigation found that the threat group launched approximately 1.16 billion authentication attempts against around 320,000 FortiGate devices. The result: 73,932 sets of confirmed, valid VPN and administrator credentials. The victim list includes global corporations such as Samsung, Foxconn(鴻海), Toyota, Siemens, and Oracle.
Why “Patched” Devices Are Still at Risk
Arctic Wolf’s analysis identified the core problem. Fortinet migrated password storage from SHA-256 to the stronger PBKDF2 scheme in FortiOS 7.2.11 and later — but if an administrator never logs in after upgrading, the old, weaker SHA-256 hash persists in the system. This means devices running the latest firmware remain vulnerable unless the password is actively changed, a blind spot that enabled breaches at massive scale.
Geographic Distribution and Impact on Japan
ITmedia’s report lists India, the United States, Taiwan, and Mexico among the most heavily affected countries, with Japan also named as an impacted nation. A NATO-affiliated defense contractor in Turkey was confirmed to have had classified military documents stolen — suggesting the involvement of state-level espionage activity well beyond ordinary financially motivated cybercrime.
Why Did FortiBleed Happen?
The Weakness Is Operational, Not Technical
What FortiBleed exposes is not a flaw in the firewall product itself but the reality that basic lapses in password hygiene put entire organizations at risk. The attackers did not rely on sophisticated exploit code — they exploited reused, outdated credentials and management interfaces directly exposed to the internet.
The Severity of a “Compromised Gatekeeper”
A firewall stands between a corporate network and the public internet, acting as the gatekeeper. When its credentials are leaked, an attacker can enter the internal network posing as a legitimate administrator. Bitsight’s report confirmed that the threat group was using compromised devices as sniffers — intercepting traffic passing through them to harvest new credentials, creating a self-propagating attack structure.
Steps Fortinet Users Must Take Immediately
Organizations running FortiGate or FortiOS products should implement the following actions without delay.
Emergency (Same Day)
- Change passwords for all FortiGate administrator accounts and SSL VPN accounts
- Terminate all active SSL VPN and administrative sessions
- Check your domain’s exposure using the FortiBleed lookup tool provided by HudsonRock
Short-Term (Within One Week)
- Update FortiOS to the latest version, then have every administrator log in once after the update to regenerate password hashes in PBKDF2 format
- Block management interface access from the internet; allow access only from trusted networks
- Enforce multi-factor authentication (MFA) on all accounts
Ongoing
- Review authentication logs going back to at least January 2026 for suspicious access
- Check for suspicious accounts such as
forticloud-sync
FortiBleed and the Evolving Threat Landscape
FortiBleed is not an isolated incident. There was the 500,000-credential FortiGate VPN leak in 2021, the mass publication by the Belsen Group in 2022, and now FortiBleed in 2026 — credential theft targeting Fortinet products is a recurring pattern.
It is also worth noting the data collection risks posed by apps such as WeChat — the lack of end-to-end encryption and the possibility of data sharing with the Chinese government are threats that corporate security teams cannot afford to overlook. As cross-border digital services become routine, everyday decisions — which apps to use, where to store credentials — now directly determine an organization’s security posture.
An unchanged network device password, a management console exposed directly to the internet — these “basic mistakes” have become the entry points exploited by nation-state-level attackers. FortiBleed is a stark reminder that the essence of cybersecurity lies not in sophisticated technical debate, but in the discipline of day-to-day operations.
References
- 美商 Fortinet 疑似登入憑證外洩 資安署発布警訊強化資安防護(経済日報)
- CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure(CISA)
- Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries(Arctic Wolf)
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices(BleepingComputer)
- Security Alert – FortiBleed Fortinet VPN Credentials and Configuration Data Exposed(Bitsight)
- パッチ適用後も標的に? 32万台超のFortiGateを襲った「FortiBleed」の正体(ITmedia)
- Security Alert – FortiBleed Credential Leak Incident(HKCERT)
- AL26-014 – FortiBleed leak of thousands of compromised credentials(Canadian Centre for Cyber Security)
- FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems(Recorded Future)


コメント