A dataset tied to the FortiBleed campaign exposed credentials associated with internet-facing Fortinet and FortiGate devices used for SSL-VPN remote access, affecting organizations in 194 countries. Researchers reported that the collection grew from roughly 73,000 compromised devices to 86,644 firewalls and VPN gateways, and included VPN URLs, usernames, email addresses, and in many cases plaintext passwords. Italian authorities warned that the circulating dataset was specifically linked to exposed SSL-VPN credentials on internet-accessible Fortinet systems.
Independent validation found that some leaked credentials were authentic and still worked on exposed devices, including systems running recent FortiOS versions. Investigators linked the database to active threat actors conducting large-scale scanning, compromising devices, intercepting traffic, and using stolen access to move into internal networks; some follow-on intrusions reportedly ended with ransomware-style encryption of hundreds of systems. Analysis also indicated that both default or built-in Fortinet accounts and organization-created accounts were present in the leak, pointing to weak credential hygiene and credential reuse as contributing factors, while the original intrusion vector remained unknown.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-19, CISA warned that credentials exposed in the FortiBleed leak were already being actively used in intrusion campaigns against FortiGate targets. The warning marked an escalation from credential exposure to observed malicious use of the leaked data.
On 2026-06-10, CSIRT Italia published a bulletin reporting the circulation of a dataset linked to the “FortiBleed” campaign. The dataset was described as containing information associated with internet-exposed Fortinet/FortiGate SSL-VPN devices and exposed credentials tied to those systems.
In June 2026, security researcher Bob Diachenko discovered an exposed server holding a large database of FortiGate and Fortinet VPN URLs, usernames, email addresses, and plaintext passwords. The leak was later described as affecting tens of thousands of devices worldwide.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecert.pa
Open sourcecolcert.gov.co
Open sourceacn.gov.it
Open sourcedocs.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.