19 Juin

Hackers leaked their own stash of 74000 cracked Fortinet firewall passwords

A Russian-speaking cybercriminal group spent months harvesting credentials from Fortinet firewalls worldwide. Then they left the whole haul on an exposed server.

Security researcher Bob Diachenko found it last weekend. The dataset, dubbed FortiBleed by threat intelligence firm Hudson Rock, contains valid admin credentials for 73,932 unique firewall URLs across 194 countries and 21,632 domains. Kevin Beaumont, who independently verified the data, said the credentials are real and that many affected devices run fairly recent patches.

The credentials did not come from a zero-day. They came from persistence and GPU power.

The operation

According to Diachenko’s analysis, the group intercepted SSL VPN authentication hashes from internet-facing FortiGate devices, then cracked them on a 45-GPU cluster managed through Hashtopolis. The exposed files referenced roughly 1.16 billion credential attempts against more than 320,000 targets. Once they had the passwords, they pivoted into internal Active Directory environments.

Here is the uncomfortable part. Fortinet switched to PBKDF2 with randomized salt for password storage in early 2025, which is far harder to crack. But many devices still store credentials using the older SHA-256 method. Those are the ones that fell. Fortinet says this is a resharing of data from previous incidents and brute-force campaigns, not a new vulnerability. That is technically true and completely beside the point. 74,000 firewalls still running crackable password hashing is the vulnerability.

Who got hit

The dataset reads like a Fortune 500 directory. Samsung, Siemens, Foxconn, Oracle, Accenture, DHL, Infosys. Fortinet itself is on the list. So are government agencies and critical infrastructure operators across healthcare, finance, telecommunications, and manufacturing.

At least four organizations were fully compromised. One of them is a Turkish NATO defense contractor whose classified defense documents were exfiltrated.

The response

CISA issued an alert on June 18 urging organizations to harden their Fortinet devices. Hong Kong’s HKCERT followed with its own security bulletin. The advice is the same everywhere: check if your organization is on the list using Hudson Rock’s free lookup tool, rotate all credentials immediately, enforce MFA on every account, upgrade to the latest FortiOS, and pull management interfaces off the public internet where possible.

Fortinet’s official position is that the leak aggregates old data. Researchers who examined the dataset disagree on the specifics but agree on the scale. Whether the credentials are freshly stolen or recycled from 2024 incidents does not change the fact that they work right now, today, against devices that are still online.

The attack surface here is not exotic. It is management interfaces exposed to the internet, running legacy password hashing, with no MFA. Every one of those boxes is a door. 74,000 of them just had their keys published.

Sources: Help Net Security, CISA, Security Boulevard, The Register, CybelAngel

Mots-cles

fortibleed fortinet firewall credentials vpn data breach hudson rock