FortiBleed Campaign Hacked 110 Million Credentials This Week

A massive credential harvesting operation leveraging the FortiBleed vulnerability has come to light. Impacting an estimated 110 million user credentials.

Across tens of thousands of FortiGate firewall and VPN gateway devices worldwide [2].

The scale of this breach places it among the most consequential network security incidents of 2026. Prompting urgent warnings from global cybersecurity agencies. Demanding immediate action from every organization running Fortinet infrastructure.

Hacked 110 Million Credentials This Week

Key Takeaways

  • The FortiBleed Campaign Harvests 110 Million Credentials This Week through exploitation of known Fortinet vulnerabilities, primarily CVE-2022-40684.
  • Between 30,000 and 430,000 FortiGate devices have been confirmed as affected, with the true number potentially higher [6].
  • A Russian-linked initial access broker, tracked as 0nyxe, is widely attributed as the primary threat actor behind the campaign [8].
  • Global cybersecurity agencies, including CISA, have issued formal warnings urging immediate patching and credential rotation [1].
  • Organizations that have not patched their Fortinet devices should treat all stored credentials as compromised.

What Is FortiBleed and How Did It Harvest 110 Million Credentials

FortiBleed refers to the active exploitation of a critical authentication bypass vulnerability in Fortinet’s FortiOS and FortiProxy products. Most notably CVE-2022-40684 [2].

Attackers exploited this flaw to access management interfaces without valid credentials. Then deployed a custom tool called FortiGateSniffer to silently capture and exfiltrate authentication data from live network traffic [3].

The operation did not rely on brute force. Instead, it used a passive sniffing technique. That intercepted credentials as they passed through compromised devices. This method made detection extremely difficult, as no unusual login attempts appeared in standard logs [4].

“The campaign represents one of the most efficient credential harvesting operations ever documented against network edge devices.” — Security Affairs [4]

Key technical facts about the attack:

FactorDetail
Primary vulnerabilityCVE-2022-40684 (auth bypass)
Tool usedFortiGateSniffer
Devices targetedFortiGate firewalls, VPN gateways
Credentials harvestedApproximately 110 million
Devices confirmed affected30,000 to 430,000 [6]
Attributed actorRussian-linked broker 0nyxe [8]

Stolen credentials included VPN usernames, passwords, and session tokens. Data that gives attackers direct access to corporate networks without triggering standard security alerts.

Tracking data on affected organizations suggests the campaign spans critical infrastructure, financial services, healthcare, and government sectors [1].


Fortibleed Hack

Russian-Linked Threat Actor Behind the FortiBleed Campaign?

Attribution for the FortiBleed Campaign Harvests 110 Million Credentials. This Week operation points strongly toward a Russian-linked initial access broker known as 0nyxe [8].

Initial access brokers specialize in compromising systems and then selling that access to other criminal groups, including ransomware operators.

Sophos researchers, who have been tracking related activity. Noted that the FortiBleed campaign ran in parallel with a separate Sophos VPN bruteforcing effort.

Suggesting a coordinated push against network edge devices across multiple vendors [9].

This pattern mirrors broader trends in state-linked cybercrime. Where threat actors target the data breach ecosystem to monetize stolen credentials at scale.

The operation also raises concerns about tracking and surveillance risks embedded in compromised network infrastructure.

Global cybersecurity agencies, including bodies across the US, UK, Canada, and Australia, issued a joint advisory warning. Organizations to treat any unpatched FortiGate device as fully compromised [1].

The advisory specifically called out the risk to encryption integrity when VPN credentials are stolen at this scale.


What Organizations Must Do Right Now

The FortiBleed Campaign Hacked 110 Million Credentials. This Week demands an immediate, structured response. Delayed action significantly increases exposure to ransomware deployment and lateral movement within corporate networks.

Immediate steps:

  • Patch now: Apply all available Fortinet security updates, particularly those addressing CVE-2022-40684 and related advisories.
  • Rotate all credentials: Assume every password and session token stored on affected devices is compromised [2].
  • Enable multi-factor authentication (MFA): MFA limits the damage of stolen passwords by requiring a second verification step.
  • Audit VPN access logs: Look for unusual login times, geographic anomalies, or new device registrations.
  • Isolate unpatched devices: Remove any unpatched FortiGate unit from production networks until remediation is complete.
  • Engage threat intelligence feeds: Monitor for your organization’s credentials appearing in underground markets.

The risk extends beyond the immediate breach. Stolen credentials from this campaign could fuel secondary attacks for months.

Organizations should also review their remote worker security posture, as VPN credentials are a primary entry point for insider-threat scenarios.

For context on how large-scale data exposure reshapes workforce and operational risk. The digital exposure of 151 million workers through AI systems offers a parallel case study in cascading data risk.


Conclusion

The FortiBleed Campaign Harvests 110 Million Credentials This Week is not a theoretical risk. It is an active, ongoing operation with confirmed victims across every major industry sector.

The combination of a known vulnerability, a sophisticated passive sniffing tool, and a well-resourced threat actor has produced one of the largest network credential thefts on record.

Actionable next steps for security teams:

  1. Verify patch status for every FortiGate and FortiProxy device in the environment today.
  2. Force a full credential reset for all accounts that authenticate through affected VPN gateways.
  3. Deploy MFA across all remote access points without exception.
  4. Report suspected compromise to national cybersecurity authorities and follow agency guidance [1].
  5. Brief executive leadership on the financial and operational exposure created by unpatched network devices.

Waiting is not a strategy. Every hour of delay extends the window for attackers to monetize stolen credentials or sell network access to ransomware groups.


References

[1] Global Cybersecurity Agencies Warn Of Credential Exposure In Fortibleed Campaign Targeting Fortinet Firewalls Vpn Gateways – https://industrialcyber.co/vulnerabilities/global-cybersecurity-agencies-warn-of-credential-exposure-in-fortibleed-campaign-targeting-fortinet-firewalls-vpn-gateways/

[2] Fortibleed Targeted Fortigate Firewalls – https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html

[3] Fortigatesniffer Harvest Credentials Firewalls – https://cyberpress.org/fortigatesniffer-harvest-credentials-firewalls/

[4] Fortibleed The Most Detailed Breakdown Yet Of An Active Russian Credential Harvesting Operation – https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation/

[6] Fortibleed Update Now 430k Fortigates Hit And 110 – https://www.reddit.com/r/sysadmin/comments/1udoilq/fortibleed_update_now_430k_fortigates_hit_and_110/

[8] Russian Initial Access Broker Behind Fortibleed Campaign – https://news.backbox.org/2026/06/23/russian-initial-access-broker-behind-fortibleed-campaign/

[9] Fortinet Fortibleed Credential Exposure And Sophos Vpn Bruteforcing Campaign – https://www.sophos.com/en-us/security-advisories/fortinet-fortibleed-credential-exposure-and-sophos-vpn-bruteforcing-campaign


Index