A large-scale campaign dubbed FortiBleed exploited weak security on Fortinet FortiGate devices to steal credentials and gain access to government and corporate networks worldwide. Researchers said the operators scanned internet-exposed FortiGate portals, logged in with default or previously leaked credentials, and in many cases deployed a Go-based sniffer known as FortigateSniffer to intercept traffic and harvest additional logins. SOCRadar estimated that more than 430,000 FortiGate firewalls were targeted, over 110 million credentials were collected, and about 12,000 devices were implanted, with activity observed across more than 150 countries.
The stolen access was then used for deeper intrusions, including attacks tied to the INC Ransom and Lynx ransomware groups. Researchers reported that 354 compromises progressed into victim environments and at least 12 cases ended in ransomware deployment that encrypted hundreds of endpoints. In the UK, exposed accounts reportedly included Foreign Office staff, embassy personnel in Thailand and Mauritius, and local government officials, while organizations linked to the NHS, energy providers, and pharmaceutical suppliers were also affected; some stolen credentials were allegedly offered for sale on criminal forums by a user called "SantaAd." The UK National Cyber Security Centre said it was tracking ongoing brute-force activity against Fortinet devices and urged organizations to inspect networks, isolate compromised systems, and reset passwords.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The UK National Cyber Security Centre confirmed ongoing brute-force activity targeting Fortinet devices and advised organizations to inspect networks, isolate compromised devices, and reset passwords. The notice was presented as an official response to the activity described in the reporting.
Reporting said the campaign led to the theft of email accounts and credentials belonging to UK government officials, Foreign Office staff, embassy personnel in Thailand and Mauritius, and local government officials in Derbyshire and Waltham Forest. The article also said credentials tied to organizations linked to the NHS, energy companies, and pharmaceutical suppliers were being offered for sale on illicit forums by a user named "SantaAd."
SOCRadar linked the FortiBleed campaign to the INC Ransom and Lynx ransomware groups, saying credentials stolen from FortiGate devices were later used to penetrate corporate networks and deploy ransomware. The researchers said 12 observed cases ended in ransomware deployment that encrypted hundreds of endpoints.
SOCRadar researchers reported finding an internet-exposed server containing stolen credentials from more than 73,000 Fortinet devices, FortiGate configuration files, and infrastructure used for hash cracking and credential stuffing. The same reporting said the broader campaign targeted over 430,000 FortiGate firewalls globally and identified persistent backdoor accounts named "adminin."
SOCRadar reported that the large-scale FortiBleed campaign had been active since at least February 2026. The operators allegedly scanned the internet for FortiGate devices, logged in with default or previously leaked credentials, and installed a Go-based sniffer called FortigateSniffer to intercept traffic and harvest credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceitpro.com
Open sourceeuronews.al
Open sourcexakep.ru
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.