FortiBleed: When 430,000 Electric Fences Forgot They Were Fences
I have been in this field long enough to remember when a firewall was something you respected. You configured it carefully, you documented every rule on paper, and you did not leave it dangling on the public internet like a lamb tied to a post with a sign that says "please do not eat me."
Apparently, that institutional memory has been thoroughly composted.
A Russian-speaking wolf, operating as what the industry now adorably calls an "initial access broker," has been quietly bleeding 430,000 FortiGate electric fences dry since February 2026. The operation, dubbed FortiBleed, has resulted in the harvesting of approximately 110 million credentials. One hundred and ten million. I need a moment.
The methodology is not sophisticated. It is not elegant. It is brute, patient, and effective, which is frankly more than I can say for the flock being targeted. The wolves collected credential lists, scanned for exposed services, brute-forced their way through unlocked gates, and deployed custom parasites to maintain access. This is not a zero-day situation. There is no mysterious hole in the fence here. The fence was simply left open.
In the 1990s, your credentials lived on a magnetic tape in a locked cabinet. A wolf had to physically be there to steal them. Now we have placed 430,000 electric fences into the Sky Pasture, pointed them at the public internet, and expressed genuine surprise when a financially motivated criminal with a dictionary and some patience walked right through.
The Shepherds, naturally, are nowhere to be found. Presumably they are in a board meeting discussing their cloud migration roadmap.
What genuinely offends me is the "bespoke malware" detail. Someone wrote custom fleas for this operation. That represents real investment, real patience, real tradecraft. And the defending side could not be bothered to apply ointment on schedule. We deserve everything we get.
Remediation
I will keep this brief because the instructions were not complicated to begin with.
First: Patch your FortiGate devices. Apply every shearing update Fortinet has issued. Do it now. Do it before you finish reading this sentence.
Second: Your FortiGate management interface should not be reachable from the public internet. If it is, you have built an electric fence and then installed a welcome mat.
Third: Audit your credentials. All 110 million of those stolen keys belonged to someone. Rotate everything, enforce multi-factor authentication, and stop using passwords that a moderately intelligent coyote could guess in an afternoon.
Fourth: Run your traffic through a sheep tunnel. A VPN is not optional decoration.
The tools to prevent this existed. They were simply not used.
Stay paranoid, the wolves certainly are.
Original Report: https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html