FortiBleed: 110 Million Credentials Stolen From the World's Firewalls
A financially motivated Russian-speaking group has been running one of the most methodical credential-harvesting operations seen this year, according to SOCRadar's full report via The Hacker News. The campaign, active since February 2026, has compromised over 430,000 FortiGate firewalls worldwide.
The attack follows a ruthless five-step playbook. First, the group scanned the internet for exposed FortiGate devices using tools like Masscan and Shodan. Then, they forced their way in through credential stuffing (trying stolen username and password combinations across many targets) and dictionary attacks against admin panels and VPN portals.
Once inside, they deployed a Golang-based (Google's programming language, often used to build fast, cross-platform tools) tool called FortigateSniffer. It exploits a built-in FortiOS diagnostic command to passively intercept live authentication traffic, like slipping a tap onto a telephone wire. The sniffer captured credentials across 24 protocols — everything from LDAP to RDP to MySQL.
The haul was staggering in its precision: 110 million credentials total, including 14.8 million RADIUS credentials, 924,000 NTLM hashes, 130,000 Kerberos hashes, and 89 million MySQL authentication tokens. Password hashes were cracked and fed into lateral movement (moving deeper through a network after initial access) across Active Directory environments.
Small and medium businesses with under 200 employees were the primary targets, particularly in IT services, the US, and India. Breaching IT service providers gives attackers a shortcut into their clients' systems.
What to do: If your organisation uses FortiGate devices, check for unrecognised SSH sessions or unexpected sniffer processes running on your firewall. Rotate all administrative credentials immediately. Enable multi-factor authentication on every exposed admin panel and VPN portal.
Sources

