The large-scale, automated campaign known as FortiBleed is still ongoing and to this point has successfully compromised more than 86,000 Fortinet firewall and VPN gateway devices across 194 countries. 

Researchers at SOCRadar discovered the operation a few days ago and found that it relied on an exposed operational server that contains the group's automated tooling, victim lists, and a database of validated credentials. The campaign is not the result of a compromise of Fortinet itself, but rather involves the attackers testing a custom list of known passwords for Fortinet devices against internet-exposed boxes and then using those compromised devices as adversary-in-the-middle points on the networks.  

The threat actors–who are likely Russian-aligned– employed a highly automated, systematic approach to compromise perimeter infrastructure. The workflow involved continuous internet-wide scanning followed by credential stuffing attacks using curated lists of credentials harvested from prior breaches.

“The attackers scan the internet for Fortinet devices, try a curated list of known passwords against each one, and record every successful login. Once a device is compromised, they use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself,” the SOCRadar analysis says.

“The password list is not random. It is a carefully assembled collection of credentials leaked from Fortinet devices in earlier incidents, meaning many targets may have never changed their passwords after a prior breach. The attackers know this, and they are counting on it.”

Data recovered from the exposed server indicates that the primary vector for entry was the exploitation of default or generic administrative credentials, showing a critical, systemic failure in password rotation policies across both corporate and government networks. After successful authentication, the threat actors converted compromised gateways into AITM boxes that gave them the ability to intercept traffic and gather additional credentials.

The SOCRadar analysis shows that the attackers were not limited to opportunistic financial theft; files included specific credentials for a defense industry VPN endpoint, suggesting strategic intelligence gathering. 

Geographic analysis of the victim data shows large clusters in the United States and India, which together account for nearly one-third of the compromised devices. The heavy targeting of NATO member nations, combined with the specific choice of tooling and infrastructure, lines up with the TTPs typically associated with Russian-speaking threat actors.

While the campaign impacted various sectors, the telecommunications and government industries emerged as the most heavily targeted verticals. Organizations that have not done so already should rotate default passwords on any internet-exposed FortiGate devices immediately.