Monday, August 3, 2026

Chips & Hardware

Fortinet firewalls hit by widespread credential-harvesting campaign

A widespread hacking campaign has compromised tens of thousands of Fortinet firewalls and VPNs all over the world, appearing to exploit credential harvesting rather than unknown software vulnerabilities.

Fortinet firewalls hit by widespread credential-harvesting campaign

Cybercriminals have compromised tens of thousands of Fortinet firewalls and Virtual Private Networks (VPNs) in an ongoing hacking campaign all over the world. The campaign, dubbed FortiBleed, appears to not involve abusing any unknown vulnerability in the targeted devices. Instead, the operation relies on a more basic issue: companies may not be changing passwords to the firewall, leaving credentials exposed to bruteforcing.

According to reports published this week by cybersecurity firms Hudson Rock and SOCRadar, the attackers use automated tools to scan the internet for exposed devices, breaking into them using lists of previously known passwords. SOCRadar, a cybersecurity firm, explained that the system feeds itself: “Once a device is compromised, [the hackers] use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself,”

Fortinet has acknowledged the activity. Tiffany Curci, a Fortinet spokesperson, stated that the company is aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways. The company added that its analysis indicates the data involved is a resharing of data from previous incidents, as well as bruteforcing of credentials, and is not related to any recent incident or advisory.

The scale of the campaign is substantial. Hudson Rock reported finding evidence suggesting that more than 73,000 unique Fortinet URLs have been hacked, while SOCRadar stated that the total number of hacked devices is more than 30,000. The countries with the most affected devices are India, the United States, Taiwan, and Mexico, though both firms noted there are victims all over the world. The breach affects companies across various industries, including IT services and government agencies. Both cybersecurity companies stated that the group behind the hacking campaign appears to be Russian-speaking. The campaign was first reported by security researcher Bob Diachenko over the weekend. On Wednesday, independent cybersecurity researcher Kevin Beaumont analyzed the data and confirmed it is legit.

According to Hudson Rock, the hacked organizations include:

  • Accenture
  • Comcast
  • Foxconn
  • Lenovo
  • Oracle
  • Samsung
  • Siemens
  • PwC

Why it matters

This incident underscores a critical shift in enterprise risk: attackers are bypassing security defenses by exploiting basic password hygiene, turning standard network infrastructure into a liability for organizations all over the world.