FortiBleed exposed valid admin and SSL VPN credentials for somewhere between 73,932 and 86,644 internet-facing FortiGate firewalls, roughly half of every FortiGate on the internet by Kevin Beaumont’s Shodan count. The headline was hash cracking, but the interesting part is quieter: after logging in, the attackers ran diagnose sniffer packet, a documented FortiOS diagnostic command, to turn compromised firewalls into passive wiretaps on the networks behind them. SOCRadar counted 659 harvest cycles between 31 May and 15 June pulling 14.8 million RADIUS records, 924,000 NTLM hashes and 130,000 Kerberos hashes off the wire. No malware, no CVE, and nothing to detect unless you were reading your own config-export logs. If you run a FortiGate with an internet-facing management interface, rotate everything and go read those logs.
The most effective tool in the FortiBleed campaign was diagnose sniffer packet, a FortiOS troubleshooting command that Fortinet documents, supports and ships in the box. No exploit involved.
SOCRadar’s threat research unit recovered the exact invocation from the attacker’s own tooling. A Go binary called FortigateSniffer, Russian-language interface, would SSH into a compromised FortiGate with credentials from a list and run:
diagnose sniffer packet any 'port 49 or port 88 or port 445 or port 389 or
port 135 or port 139 or port 143 or port 110 or port 25 or port 21 or port 23
or port 3389 or port 5985 or port 5986 or port 636 or port 3268 or port 1433
or port 3306 or port 5432 or port 6162 or port 1812 or port 1813 or port 1645
or port 1646' 6 0 a
Read the port list. TACACS+, Kerberos, SMB, LDAP, RPC, IMAP, POP3, SMTP, FTP, telnet, RDP, WinRM, LDAPS, the global catalog, MSSQL, MySQL, Postgres, RADIUS auth and accounting. That is every protocol on a corporate network that carries a password, tapped at the one device all of it flows through. Verbosity level 6 gives full packet hex. The 0 means capture until stopped.
What a firewall hears
The output of that command, parsed at scale, is the campaign. Between 31 May and 15 June the operators ran 659 harvest cycles across their compromised estate. The aggregate files SOCRadar recovered hold 14.8 million RADIUS records, 924,000 NTLM hashes, 130,000 Kerberos hashes and 89 million MySQL auth tokens. One target list held 237,330 working FortiGate SSH credentials. At the time SOCRadar published, roughly 19,000 devices were still actively being sniffed.
The tool wrote its output straight into Hashcat-ready files, split by mode: NTLMv2, NTLMv1, Kerberos 5 pre-auth AES256, AS-REP RC4, TGS AES256. Cracking ran through a Hashtopolis instance on the attacker’s server. CloudSEK, which got into the same open directory at 85.11.187.8:9999 before it went dark, found the operator’s own logs and deflated one detail of the reporting. The “dedicated GPU cluster” was six rented Vast.ai instances totalling about 36 GPUs, billed by the hour on somebody’s card.
The hash upgrade that mostly didn’t happen
Initial access came from config exports. FortiGate devices keep admin password hashes in the device configuration, so a config backup is a credential file with a network diagram attached.
Fortinet moved admin credential storage from salted SHA-256 to PBKDF2 in FortiOS 7.2.11, 7.4.8 and 7.6.1, released in late 2025, after Beaumont’s reporting on the Belsen Group leak. The migration has a condition: each admin’s hash only upgrades when that admin logs in after the firmware update. Accounts nobody has touched since the patch still sit there as salted SHA-256, which a rented GPU eats for breakfast.
The Cloud Security Alliance’s research note adds the part that should worry you more. A backward-compatibility mechanism keeps the old SHA-256 hash in a hidden old-password field. You can’t see it in the management interface. It is fully present in any config backup a super_admin takes. Devices whose admins had dutifully logged in and upgraded to PBKDF2 were still handing over a crackable legacy hash to anyone who pulled the config.
CSA also found that about 63% of the compromised accounts were either built-in Fortinet system accounts or generic admin names nobody had renamed.
”Reusing credentials from previous incidents”
On 19 June, Fortinet CISO Carl Windsor published a PSIRT post attributing the campaign to “threat actors reusing credentials from previous incidents” plus brute force against “devices with weak password hygiene and no multi-factor authentication,” and stated flatly: “This is not a new Fortinet vulnerability.”
Beaumont, who was working directly with victim organisations and getting their logs in return, disagreed: “Fortinet told media orgs the data was from prior breaches and bruteforcing. That isn’t true.” Every organisation he helped had experienced config exports within the previous month, visible in FortiOS system event logs, performed seconds after login by a mix of admin and REST API accounts. He published the source IPs. One of them, 96.45.42.173, belongs to Fortinet’s own ASN and their SASE product. His note on it: “no, I don’t know how this is happening.”
In FortiOS, go to System → Events and filter messages for config (or *config*, depending on version). Config exports are logged with the account that performed them. Beaumont’s victim IP list and the FortiGuard-ID domain list are both public.
The gap
Nobody agrees on the number. Diachenko and Recorded Future say 73,932 firewall URLs across 194 countries. SOCRadar says 86,644, with 430,000 devices targeted overall and 110 million credentials collected. Beaumont’s Shodan comparison puts the confirmed set at roughly half of all internet-facing FortiGates. CloudSEK argues only about a thousand organisations were provably compromised internally, which Beaumont thinks understates it and which is, in any case, a thousand organisations.
CISA issued its advisory on 18 June. The HN thread on Beaumont’s first post is short and mostly resigned; one commenter offers that the vendor is known in the trade as “Faultygate,” another asks when companies will stop buying products like this, and gets the answer: they won’t.
Beaumont’s own conclusion is the one worth keeping. Organisations are spending their anxiety budget on frontier AI threats while tens of thousands of them run internet-exposed VPN concentrators with no MFA. SOCRadar found traces of CyberStrike, an open-source autonomous pentest agent, in the harvesting pipeline, so the AI angle is real enough. It sat on top of three much older load-bearing failures: an exposed management interface, a legacy hash format, and a diagnostic command working exactly as designed.
Sources
- SOCRadar, FortiBleed 2026: 86,644 Fortinet Firewalls Compromised and the full Dismantling FortiBleed report (PDF)
- Kevin Beaumont, FortiBleed: 75k Fortinet firewalls have admin passwords cracked (17 June 2026) and An update on FortiBleed (19 June 2026)
- CloudSEK, Inside the FortiBleed Open Directory
- Recorded Future Insikt Group, FortiBleed Campaign Exposes Credentials for 73,932 FortiGate Systems (24 June 2026)
- Fortinet PSIRT, Analysis of Reported Credential Compromise of FortiGate Devices (19 June 2026)
- Cloud Security Alliance, FortiBleed: Default Credential Exploitation and Mass Fortinet Compromise (20 June 2026); CISA advisory (18 June 2026); Arctic Wolf; Hudson Rock lookup tool
Related on this blog
- Three Indirection Steps From a Reverse Shell: the same lesson about trust boundaries, one abstraction layer up
- The Story of Skills: How a Fake Plugin Hijacked 26,000 AI Agents: what happens when the attacker’s tooling is the defender’s tooling