SUBJECT PROFILE
Active since at least February 2026, FortiBleed is the largest confirmed Fortinet credential-harvesting campaign in history, compromising verified admin and SSL VPN credentials for 86,644 FortiGate devices across 194 countries — roughly 50% of all internet-facing Fortinet firewalls globally. The Russian-speaking IAB deployed a custom Golang-based tool (FortigateSniffer) to passively capture cleartext credentials passing through compromised firewalls, cracked hashes via a 45-GPU Hashtopolis cluster, and pivoted into Active Directory environments. A NATO defense contractor was confirmed compromised with classified documents exfiltrated on June 15. CISA, UK NCSC, and Fortinet all issued emergency advisories by June 18–19, 2026.
Financially motivated initial access brokerage — large-scale automated credential harvesting of FortiGate firewalls for resale to ransomware gangs and potentially Russian state-sponsored APTs
OPERATIONAL HISTORY
Mass scanning via Masscan/Shodan (T1595), SSH brute-force against FortiGate (T1110), passive network sniffing via FortiOS diagnostic abuse (T1040), Kerberos hash cracking (T1558), credential stuffing from prior breach datasets (T1110.004), Active Directory lateral movement (T1021), DFS backup exfiltration (T1039), credential marketplace sales
KNOWN INFRASTRUCTURE
FortigateSniffer (custom Golang sniffer), CyberStrikeAI autonomous scanning framework, 45-GPU Hashtopolis cracking cluster, automated validation scripts, structured dark web sales infrastructure (Exploit Forum alias SantaAd listing access at $30,000–$60,000); campaign also targeting Sophos SSL-VPN, Synology NAS, Citrix, RDWeb, MSSQL