{"id":80768,"date":"2026-06-19T15:19:09","date_gmt":"2026-06-19T08:19:09","guid":{"rendered":"https:\/\/itsystems.vn\/?p=80768"},"modified":"2026-07-29T11:24:51","modified_gmt":"2026-07-29T04:24:51","slug":"fortibleed-leak-of-30000-fortinet-login-credentials","status":"publish","type":"post","link":"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/","title":{"rendered":"FortiBleed: Massive Credential Leak Campaign Exposes Over 30,000 Fortinet Devices Worldwide"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">The content of the article<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#FortiBleed_and_the_Stark_Warning_for_Enterprise_Security_Systems\" >FortiBleed and the Stark Warning for Enterprise Security Systems<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#How_the_FortiBleed_Campaign_Was_Discovered\" >How the FortiBleed Campaign Was Discovered<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#The_Massive_Scale_of_the_FortiBleed_Data_Breach\" >The Massive Scale of the FortiBleed Data Breach<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Global_Impact_of_the_FortiGate_Security_Breach\" >Global Impact of the FortiGate Security Breach<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#How_the_Credential_Harvesting_Attack_Works\" >How the Credential Harvesting Attack Works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Sensitive_Information_Collected_and_Potential_Risks\" >Sensitive Information Collected and Potential Risks<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Why_Fortinet_Users_Must_Act_Immediately\" >Why Fortinet Users Must Act Immediately<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Emergency_Response_Recommendations_for_Businesses\" >Emergency Response Recommendations for Businesses<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Technical_Recommendations_from_Vendors_and_Experts\" >Technical Recommendations from Vendors and Experts<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Key_Lessons_and_the_Broader_Context_of_FortiBleed\" >Key Lessons and the Broader Context of FortiBleed<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Related_services_from_IT_Systems\" >Related services from IT Systems<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#FAQ\" >FAQ<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#When_should_a_business_ask_IT_Systems_for_support\" >When should a business ask IT Systems for support?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Can_IT_Systems_help_review_the_current_environment_before_proposing_a_solution\" >Can IT Systems help review the current environment before proposing a solution?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Does_this_topic_connect_to_ongoing_IT_operations\" >Does this topic connect to ongoing IT operations?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/itsystems.vn\/en\/fortibleed-leak-of-30000-fortinet-login-credentials\/#Need_help_applying_this_to_your_business\" >Need help applying this to your business?<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"FortiBleed_and_the_Stark_Warning_for_Enterprise_Security_Systems\"><\/span>FortiBleed and the Stark Warning for Enterprise Security Systems<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The <strong>FortiBleed<\/strong> campaign is sending shockwaves through the global cybersecurity community. It is a large-scale <strong>credential harvesting<\/strong> operation targeting Fortinet FortiGate firewalls and VPN gateways. With more than 30,000 devices already compromised and a verified database of active login credentials, this incident poses a severe threat to businesses, government organizations, and critical infrastructure worldwide. Once again, exposing security devices directly to the internet has proven to be a fatal mistake.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_the_FortiBleed_Campaign_Was_Discovered\"><\/span>How the FortiBleed Campaign Was Discovered<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>In mid-June 2024, security researchers detected signs of a highly organized active campaign. They named it <strong>FortiBleed<\/strong>. The threat actors used sophisticated methods to extract configuration files from publicly exposed FortiGate devices on the internet. After obtaining these files, they cracked the stored password hashes.<\/p>\n<p>As a result, attackers now possess tens of thousands of valid administrator credentials. This was not random password spraying but a targeted attack that directly exploited configuration data and stored secrets.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_Massive_Scale_of_the_FortiBleed_Data_Breach\"><\/span>The Massive Scale of the FortiBleed Data Breach<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The leaked data contains exactly 30,791 verified active <strong>Fortinet login credentials<\/strong>. Independent research estimates the actual impact could reach approximately 75,000 devices. Alarmingly, the entire dataset was professionally organized by country, industry, and organizational revenue. This systematic categorization indicates the campaign was carried out by a highly organized group, not amateur hackers.<\/p>\n<p>In reality, the true number may be significantly higher as many organizations have not publicly disclosed breaches or have yet to detect signs of compromise.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Global_Impact_of_the_FortiGate_Security_Breach\"><\/span>Global Impact of the FortiGate Security Breach<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The <strong>FortiBleed<\/strong> campaign has spread across 194 countries and territories. From multinational corporations in the United States and Europe to government agencies in Asia, Africa, and South America &#8211; all have been targeted. Beyond private enterprises, numerous state organizations and critical infrastructure have also been affected.<\/p>\n<p>This is clearly not a localized incident or limited to a specific industry. Instead, it represents a large-scale intelligence-gathering operation that could serve as a foundation for future attacks such as ransomware, APTs, or cyber espionage.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_the_Credential_Harvesting_Attack_Works\"><\/span>How the Credential Harvesting Attack Works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Unlike traditional brute-force attacks, <strong>FortiBleed<\/strong> focuses on exploiting device configuration files. When a FortiGate is exposed to the internet via its management port (typically HTTPS port 443 or 10443), attackers attempt to download the encrypted config file. This file contains password hashes and other authentication data.<\/p>\n<p>After decrypting and cracking the hashes (especially weaker ones found in older FortiOS versions), attackers obtain actual usernames and passwords. This method is far more effective than mass password guessing because it directly leverages secrets already stored on the device.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Sensitive_Information_Collected_and_Potential_Risks\"><\/span>Sensitive Information Collected and Potential Risks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The exposed data includes administrator credentials, VPN accounts, and in some cases, admin emails, plaintext passwords, and session information. With this data, attackers can easily access internal networks, perform lateral movement, deploy ransomware, or steal sensitive information.<\/p>\n<p>A real-world example involves hospitals using FortiGate to connect PACS systems and electronic medical records. If VPN accounts are abused, the personal health data of millions of patients could be stolen or encrypted for ransom.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Why_Fortinet_Users_Must_Act_Immediately\"><\/span>Why Fortinet Users Must Act Immediately<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The greatest danger of <strong>Fortinet credential leaks<\/strong> is that compromised credentials remain valid even after patching. Many organizations believe updating firmware is sufficient, but failing to change all administrative and VPN passwords leaves the backdoor wide open.<\/p>\n<p>Attackers can use these credentials to bypass firewalls, establish persistence, or sell the data on the dark web. The risk is even higher for organizations in finance, energy, healthcare, and government sectors &#8211; frequent targets of APT campaigns.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Emergency_Response_Recommendations_for_Businesses\"><\/span>Emergency Response Recommendations for Businesses<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To immediately reduce risk, organizations should take the following actions:<\/p>\n<ul>\n<li>Immediately change all administrative and VPN passwords on every FortiGate device, especially those exposed to the internet.<\/li>\n<li>Enable Multi-Factor Authentication (MFA) for all administrative and VPN accounts.<\/li>\n<li>Minimize exposure of management interfaces to the internet. Allow access only from internal IPs or through properly secured VPNs.<\/li>\n<li>Review device logs for signs of suspicious logins, configuration changes, or anomalous traffic.<\/li>\n<li>Deploy continuous monitoring solutions (SIEM) to detect lateral movement within the network early.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"Technical_Recommendations_from_Vendors_and_Experts\"><\/span>Technical Recommendations from Vendors and Experts<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Fortinet recommends that all users upgrade to the latest FortiOS version to address related vulnerabilities. After upgrading, all administrators must log in again to migrate to stronger encryption mechanisms.<\/p>\n<p>For FortiOS 7.2.x and 7.4.x versions, enable the &#8220;login-lockout-upon-weaker-encryption&#8221; setting to completely remove any remaining weak SHA-256 hashes from old passwords. Additionally, enabling strong password policies and conducting regular configuration audits is essential.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Key_Lessons_and_the_Broader_Context_of_FortiBleed\"><\/span>Key Lessons and the Broader Context of FortiBleed<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This is one of the largest publicly disclosed firewall credential leak campaigns in recent years. It underscores that patching software alone is insufficient if exposed credentials are not thoroughly changed. <strong>FortiBleed<\/strong> is a clear example of the risks of exposing critical security devices directly to the internet without proper protection layers.<\/p>\n<p>In an era of increasing credential-based attacks, organizations must shift from &#8220;defense-in-depth&#8221; to a genuine Zero Trust model, combined with continuous monitoring and strict identity management. Details about this campaign can be found in the <a href=\"https:\/\/cybernews.com\/security\/hackers-database-30000-working-fortinet-logins\/?utm_source=cn_facebook&amp;utm_medium=social&amp;utm_campaign=cybernews&amp;utm_content=post&amp;source=cn_facebook&amp;medium=social&amp;campaign=cybernews&amp;content=post&amp;fbclid=IwRlRTSASh2mhleHRuA2FlbQIxMQBzcnRjBmFwcF9pZAo2NjI4NTY4Mzc5AAEeNOrmirEx4Po7XO6jayEvIxDFN6yWPJpLn1i-4_GxTixq3FQTL-w_UQt7uC0_aem_I4uL5FYRCHElhQ2BZA63iA\" target=\"_blank\" rel=\"noopener\">original article on Cybernews<\/a>.<br \/>\n<!-- its-deep-aio-en-related-2026-07-27 --><\/p>\n<section class=\"its-deep-aio-related\" aria-label=\"Related IT Systems services\">\n<h2><span class=\"ez-toc-section\" id=\"Related_services_from_IT_Systems\"><\/span>Related services from IT Systems<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>If your team is dealing with this issue in a live business environment, these services can help you move from diagnosis to a stable operating process.<\/p>\n<ul>\n<li><a href=\"https:\/\/itsystems.vn\/en\/microsoft-business-licensing\/microsoft-windows-licensing\/\">Windows licensing for business<\/a><\/li>\n<li><a href=\"https:\/\/itsystems.vn\/en\/microsoft-business-licensing\/windows-license-pricing\/\">Windows license pricing<\/a><\/li>\n<li><a href=\"https:\/\/itsystems.vn\/en\/it-services-for-businesses\/it-support-services\/\">IT support services<\/a><\/li>\n<\/ul>\n<\/section>\n<p><!-- its-deep-aio-en-faq-2026-07-27 --><\/p>\n<section class=\"its-deep-aio-faq\" aria-label=\"Frequently asked questions\">\n<h2><span class=\"ez-toc-section\" id=\"FAQ\"><\/span>FAQ<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"When_should_a_business_ask_IT_Systems_for_support\"><\/span>When should a business ask IT Systems for support?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Ask for support when the issue affects users, business data, security, licensing compliance, service availability or daily operations. A short technical review often prevents repeated incidents and hidden costs.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Can_IT_Systems_help_review_the_current_environment_before_proposing_a_solution\"><\/span>Can IT Systems help review the current environment before proposing a solution?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Yes. IT Systems can review the current setup, identify risks, map the issue to the right service scope and recommend a practical next step for your business.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Does_this_topic_connect_to_ongoing_IT_operations\"><\/span>Does this topic connect to ongoing IT operations?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>In most cases, yes. Problems around software, cloud, endpoint, network, backup or security should be connected to a broader IT operations plan instead of being handled as isolated incidents.<\/p>\n<\/section>\n<p><!-- its-deep-aio-en-cta-2026-07-27 --><\/p>\n<section class=\"its-deep-aio-cta\" aria-label=\"Contact IT Systems\">\n<h2><span class=\"ez-toc-section\" id=\"Need_help_applying_this_to_your_business\"><\/span>Need help applying this to your business?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>IT Systems Vietnam can help assess the issue, recommend the right service path and support implementation for your team.<\/p>\n<p><a class=\"button\" href=\"https:\/\/itsystems.vn\/en\/contact-it-systems-vietnam\/\">Contact IT Systems<\/a> <a class=\"button\" href=\"https:\/\/itsystems.vn\/en\/it-services-for-businesses\/it-support-services\/\">View IT support services<\/a><\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>FortiBleed and the Stark Warning for Enterprise Security Systems The FortiBleed campaign is sending shockwaves through the global cybersecurity community. It is a large-scale credential harvesting operation targeting Fortinet FortiGate firewalls and VPN gateways. With more than 30,000 devices already compromised and a verified database of active login credentials, this incident poses a severe threat [&hellip;]<\/p>\n","protected":false},"author":54,"featured_media":80766,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_focus_keyword":"FortiBleed,Fortinet credential leak, credential harvesting, FortiGate security","rank_math_title":"","rank_math_description":"FortiBleed is a large-scale credential harvesting campaign targeting Fortinet devices, resulting in over 30,000 FortiGate systems leaking login credentials. Learn about the attack techniques, global impact, and urgent protection guidance.","rank_math_robots":"","rank_math_canonical_url":"","rank_math_schema":"","footnotes":""},"categories":[1344],"tags":[],"class_list":["post-80768","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized-en"],"wpml_current_locale":"en_US","wpml_translations":{"vi_VN":{"locale":"vi_VN","id":80765,"slug":"fortibleed-lo-thong-tin-dang-nhap-fortinet-30000-thiet-bi","post_title":"FortiBleed: Chi\u1ebfn D\u1ecbch L\u1ed9 Th\u00f4ng Tin \u0110\u0103ng Nh\u1eadp Fortinet \u1ea2nh H\u01b0\u1edfng H\u01a1n 30.000 Thi\u1ebft B\u1ecb To\u00e0n C\u1ea7u","href":"https:\/\/itsystems.vn\/fortibleed-lo-thong-tin-dang-nhap-fortinet-30000-thiet-bi\/"}},"_links":{"self":[{"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/posts\/80768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/users\/54"}],"replies":[{"embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/comments?post=80768"}],"version-history":[{"count":4,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/posts\/80768\/revisions"}],"predecessor-version":[{"id":85859,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/posts\/80768\/revisions\/85859"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/media\/80766"}],"wp:attachment":[{"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/media?parent=80768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/categories?post=80768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/tags?post=80768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}