
Cybercriminals Compromise Tens of Thousands of Fortinet Firewalls Worldwide
A hacking campaign dubbed 'FortiBleed' has reportedly compromised over 73,000 Fortinet devices globally, exposing major companies to risk due to poor password management.
Cybercriminals have reportedly breached tens of thousands of Fortinet firewalls and VPNs utilized by numerous major corporations globally, as indicated by two cybersecurity firms, Hudson Rock and SOCRadar.
This extensive hacking initiative, named FortiBleed, does not appear to exploit any unknown vulnerabilities in the targeted devices. Instead, it highlights a fundamental issue: companies may not be adequately changing their firewall passwords or ensuring that the credentials used for sensitive internet-exposed systems are not already compromised.
The attack begins with hackers employing automated tools to scan the internet for vulnerable Fortinet firewalls and VPNs. They subsequently gain access using lists of known passwords. Once they infiltrate a device, cybercriminals can extract more sensitive data from the targeted companies, as outlined in the reports released this week by Hudson Rock and SOCRadar.
According to SOCRadar, once the hackers have compromised a device, they utilize it as a monitoring station, observing traffic that passes through and collecting additional credentials. The newly acquired passwords are then used to compromise even more devices, creating a self-perpetuating cycle of attacks.
Tiffany Curci, a spokesperson for Fortinet, informed TechCrunch that the company is aware of a reported third-party campaign focused on harvesting credentials from Fortinet firewalls and VPN gateways. Fortinet’s analysis indicates that the data involved is a rehash of information from prior incidents and the result of brute-forcing credentials, rather than stemming from any recent incidents or advisories.

Hudson Rock reported evidence suggesting that over 73,000 unique URLs associated with Fortinet have been compromised, while SOCRadar noted that the total number of hacked devices exceeds 30,000.
Among the companies affected by this breach are well-known names such as Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC. A spokesperson for Lenovo acknowledged receipt of TechCrunch's request for comment but did not provide further details, and none of the other companies have responded to requests for comment.
The cybersecurity firms pinpointed countries with the highest number of affected devices as India, the United States, Taiwan, and Mexico, although they noted that victims exist worldwide. Hudson Rock identified the most impacted industries as IT services, construction materials, and telecommunications, while SOCRadar indicated that government agencies are also among those affected. Both firms mentioned that the group behind this hacking campaign appears to be Russian-speaking.
The findings from Hudson Rock and SOCRadar stem from the discovery of a list of credentials tied to Fortinet devices and their associated companies. The initial report of this hacking campaign was made by security researcher Bob Diachenko over the previous weekend. Independent cybersecurity researcher Kevin Beaumont corroborated the legitimacy of the data in a blog post on Wednesday after conducting his analysis.
In recent years, Fortinet devices have been the target of several hacking campaigns that typically exploited vulnerabilities within those systems. However, this case stands out as the attackers are leveraging leaked passwords, representing a more straightforward and less complex form of attack.



