BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Massive FortiBleed Attack Hits Over 430,000 Firewalls

FortiBleed hackers steal 110 million credentials from 430000 firewalls targeting SMBs

  • A financially-motivated initial access broker has targeted over 430,000 FortiGate firewalls globally since February 2026.
  • The FortiBleed operation uses a custom tool to harvest over 110 million credentials, including hashed passwords and authentication tokens.
  • The campaign heavily targets Small and Medium Businesses (SMBs), especially in the IT services sector, to gain access to downstream customer environments.
  • Attackers use a Telegram bot named HASHBOT to orchestrate hash cracking and sell access to compromised devices for up to $60,000.

A Russian-speaking threat actor has orchestrated a massive credential-harvesting campaign, dubbed FortiBleed, which has compromised more than 430,000 Fortinet firewalls globally since February 2026. The financially-motivated operation leverages a custom Golang sniffer to steal authentication data from infected devices, according to a fresh report published by SOCRadar.

- Advertisement -

The campaign specifically targets the FortiGate administrative panel and SSL-VPN portal using credential stuffing attacks. Consequently, a tool called FortigateSniffer is deployed to capture cleartext passwords and hashes from 24 different network protocols.

Stolen credentials are then cracked using tools like Hashmat and Hashtopolis, orchestrated by a Telegram bot. Meanwhile, data captured by SpyCloud shows the operation runs in five-hour cycles with a high validation success rate.

The attackers focus heavily on Small and Medium Businesses, particularly in the IT services sector within the United States and India. This strategic targeting aims to maximize downstream access into customer networks through compromised service providers.

However, FortiBleed is part of a broader, multi-vendor operation that also breaches Synology, Sophos, and Citrix systems. The campaign has identified over 110 million credentials, including 14.8 million RADIUS credentials and 89 million MySQL tokens.

- Advertisement -

The group meticulously ranks targets by economic value before allocating exploitation resources. Furthermore, their sniffing activity is geofenced and restricted to Moscow business hours, as detailed in the SOCRadar report.

Access to thousands of compromised Fortinet devices is being advertised online by an entity named SantaAd. The initial asking price was $30,000, but it was quickly raised to $60,000 shortly after being advertised.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Battles ETF Outflows and Bearish Sentiment

Ethereum's ETH price corrected 5% on Tuesday, erasing 12 days of gains and causing...

Sonic Labs Keeps Fantom Opera Open

Fantom Opera will remain live with a funded bridge until at least year-end, reversing...

Catholic Leaders Oppose Crypto Clarity Act Over Trafficking

A coalition of Catholic leaders urged U.S. Senate leaders to oppose a key section...

Cardano wallets drained, $2.4M lost in SecondFi exploit

SecondFi's wallet generation software was exploited, draining roughly 16 million ADA (~$2.4 million).The company...

Bitcoin OGs Cut Spending to Lowest Level in 19 Months

Bitcoin holders who acquired their coins over five years ago have reduced their spending...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading