Exclusive: A massive, automated credential harvesting operation has compromised tens of thousands of network perimeter devices globally, attributed to sophisticated ransomware syndicates.

GLOBAL, July 13, 2026 — In a momentous disclosure that has sent shockwaves through the cybersecurity community, threat intelligence researchers have uncovered "FortiBleed," an active and large-scale credential harvesting campaign targeting Fortinet FortiGate firewalls x.com . The operation has exposed verified administrator and SSL VPN credentials for over 86,000 internet-facing devices across 194 countries, marking one of the most pervasive network perimeter compromises in history socradar.io .

The apogee of this investigation was reached by the SOCRadar Threat Research Unit (STRU), which independently discovered and analyzed the full operation after an exposed attacker server was initially flagged by security researcher Volodymyr Diachenko socradar.io . The campaign, active since at least February 2026, operates in two self-reinforcing stages: automated credential reuse from historical breach dumps, and passive harvesting of SSL VPN traffic from already compromised devices acting as listening posts socradar.io .

Attacker Attribution and Methodology

Forensic analysis of the operational infrastructure has yielded definitive attribution. The tooling, infrastructure choices, and victim selection—heavily weighted toward organizations in NATO member countries—align with Russian-speaking threat actors socradar.io . SOCRadar has formally linked the FortiBleed campaign to the Lynx and INC ransomware groups, known for targeting healthcare, education, government, and manufacturing sectors across North America and Europe industrialcyber.co .

The attack does not rely on a novel zero-day exploit. Instead, it exploits a foundational flaw in legacy FortiOS credential management www.bitsight.com . When devices are upgraded from older versions, administrator passwords remain stored as weak SHA-256 hashes until an administrator manually logs in post-upgrade www.bitsight.com . Attackers leveraged a 45-GPU offline cracking infrastructure to systematically break these hashes at scale, yielding validated working credentials for tens of thousands of devices www.bitsight.com .

Key Threat Intelligence Findings

  • Scale: 86,644 compromised devices across 194 countries, affecting roughly 50% of all internet-reachable FortiGate appliances socradar.io .
  • Attribution: Linked to Lynx / INC ransomware operations, with post-exploitation tooling including Chisel and Neo-reGeorg observed in related activity www.bitsight.com .
  • Vector: Automated credential stuffing combined with offline SHA-256 hash cracking, not a new zero-day vulnerability socradar.io .
  • Impact: Unauthorized network access, firewall rule manipulation, and staging for ransomware deployment or data exfiltration www.bitsight.com .

Global Sector Impact

The victim list spans every sector of the global economy. Telecom operators represent one of the most heavily targeted sectors, which is particularly alarming given that telecom infrastructure underpins communications for all other industries socradar.io . Government entities account for hundreds of entries across multiple domains, carrying national security implications well beyond the raw device counts socradar.io .

Enterprise organizations with revenues exceeding $1 billion account for over 20% of all entries, representing significant financial and critical infrastructure exposure socradar.io . The ubiquitous nature of Fortinet deployments means that no region or industry has been spared from this systematic campaign socradar.io .

Immediate Mitigation Strategies

Security agencies and threat intelligence firms universally recommend treating any potentially exposed credentials as compromised. Organizations must immediately rotate all administrator and SSL VPN credentials across FortiGate devices, regardless of whether compromise has been explicitly confirmed www.bitsight.com .

Furthermore, defenders must upgrade affected devices to fixed FortiOS versions (7.2.11, 7.4.8, 7.6.1, or later) and, critically, force a hash re-authentication by logging in post-upgrade to trigger migration to stronger PBKDF2-based password hashing www.bitsight.com . Restricting external access to management interfaces and enforcing multi-factor authentication (MFA) remain the most potent controls against this type of credential-based attack www.bitsight.com .

As the threat landscape continues to evolve, the FortiBleed campaign serves as a cautionary tale about the dangers of legacy credential management and the extreme lengths to which modern cybercriminal syndicates will go to compromise network perimeters.

Official Sources & Threat Intelligence

SOCRadar Full Technical Report: Dismantling FortiBleed: Inside a Russian Fortinet Compromise Operation

Bitsight Security Alert: FortiBleed Security Alert: Fortinet VPN Credentials Exposed

Published: July 13, 2026

Official Social Media Announcement

SOCRadar (@socradar) - June 2026: