Cybercriminals have breached tens of thousands of Fortinet firewalls and VPNs used by major companies worldwide, according to two cybersecurity firms. The ongoing hacking campaign, dubbed FortiBleed, does not appear to be exploiting unknown vulnerabilities in the targeted devices. Instead, it highlights a more fundamental issue: companies may not be changing passwords for their firewalls or ensuring that credentials used for sensitive systems exposed online are not already known to hackers.
See also: Russian group exploits weak Fortinet firewalls via AI

Fortinet, known for developing advanced cybersecurity solutions, has been at the center of several attacks in recent years. Its devices, such as firewalls and VPNs, are widely used by businesses to protect their networks from external threats. However, the FortiBleed campaign highlights that technology alone is not enough to protect data if it is not accompanied by good security practices on the part of users.
In this campaign, hackers first use automated tools to scan the internet for exposed Fortinet firewalls and VPNs. They then compromise devices using lists of already known passwords. This attack method, known as credential stuffing, exploits users’ tendency to reuse passwords across multiple platforms.
Once compromised, cybercriminals can steal more sensitive data from victim companies, as cybersecurity firms Hudson Rock and SOCRadar.
“Once a device is compromised, [hackers] use it as a listening point, monitoring the traffic that passes through and collecting any additional credentials that flow in. These fresh passwords are then fed back into the scanner to compromise even more devices. The system feeds itself,” SOCRadar said. This self-perpetuating nature of the campaign makes it particularly difficult to combat, as each successful breach strengthens the attackers’ ability to continue their campaign.
See also: Fortinet FortiSandbox: Exploiting three critical vulnerabilities

Hudson Rock found evidence suggesting that more than 73,000 unique Fortinet URLs have been compromised, while SOCRadar reported that the total number of compromised devices exceeds 30,000. The companies compromised include Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens and PwC. A Lenovo spokesperson acknowledged receiving a request for comment but did not respond. None of the other companies provided comment.
According to Hudson Rock and SOCRadar, the countries with the most affected devices are India, the United States, Taiwan and Mexico, although victims are found worldwide. The most affected industries include IT services, construction materials and telecommunications, with government agencies also among the victims. Both cybersecurity firms indicate that the group behind the hacking campaign appears to be Russian-speaking.
The Hudson Rock and SOCRadar reports are based on the discovery of a list of credentials for Fortinet devices and related companies. This hacking campaign was first reported by security researcher Bob Diachenko. Independent cybersecurity researcher Kevin Beaumont confirmed the legitimacy of the data in a blog post.
In recent years, several hacking campaigns have targeted and compromised Fortinet devices, usually exploiting vulnerabilities in these systems. In this case, however, the hackers relied on leaked passwords, representing a simpler and less sophisticated attack. This highlights the need for companies to adopt more stringent password management policies, such as using unique and strong passwords, changing them regularly, and implementing multi-factor authentication (MFA).
See also: Ivanti, Fortinet, SAP: Updates for multiple critical vulnerabilities

Fortinet, for its part, continues to provide security updates and guidance to better protect its devices. However, the responsibility for implementing these security measures lies with the businesses themselves. The FortiBleed campaign serves as a powerful reminder that cybersecurity requires constant vigilance and adaptation to new threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
