An Tran Solutions
An Tran Solutions
Back to Blog

Nearly Half of Internet-Facing Fortinet Firewalls Were Just Compromised, and the Culprit Was Old Passwords

July 7, 20264 min readby An Tran
On this page

Whenever cyberattacks come up, people picture a genius hacker exploiting a zero-day, or lately, an AI writing its own attack code. It sounds frightening, and it's also convenient, because it implies there's nothing you can do, so you might as well not worry.

The biggest breach of mid-2026 used almost nothing new. It reused old passwords. And it took over roughly half of all Fortinet firewalls exposed to the internet worldwide.

The campaign is called FortiBleed. Its details are a chilling reminder: the thing that takes you down is rarely cutting-edge technology. It's the basics no one bothered to do.

What happened

According to Arctic Wolf, FortiBleed is a large-scale credential-theft campaign targeting Fortinet FortiGate firewalls and SSL VPN gateways across 194 countries. Researcher Volodymyr "Bob" Diachenko discovered the attackers' exposed server, and the incident was disclosed on June 16, 2026, but the campaign had been quietly running since at least February 2026, according to SOCRadar.

The scale figures vary by source and method, but they all point to the same alarming conclusion:

  • SOCRadar counted 86,644 affected Fortinet devices in total.
  • Bitsight confirmed more than 73,000 devices with valid admin credentials exposed.
  • Both estimate this is around 50% of all internet-facing FortiGate devices worldwide.

In other words: if your organization runs a FortiGate open to the internet, the odds it's on the list are a coin flip. This isn't hypothetical. The credentials are being sold on criminal forums, Telegram, and paste sites, according to Bitsight.

What "sophisticated" thing did the attackers do? Almost nothing.

This is what makes FortiBleed worth writing about. It wasn't a stroke of genius. It was victims' laziness, automated at scale.

The mechanism has two layers, and it feeds itself, per Arctic Wolf's description:

  1. Password reuse. The attackers collected usernames and passwords from earlier Fortinet leaks and from infostealer malware logs, then tried them automatically, around the clock, against internet-facing FortiGate devices.
  2. Passive eavesdropping. Once inside a device, they turned it into a listening post: SSL VPN traffic passing through was monitored, more credentials were harvested, and those were fed back into the scanner. A self-sustaining loop.

For devices without a ready-made password, the attackers pulled the configuration file and cracked the password hashes. Why could they? This is the root of the problem: older FortiOS versions stored admin passwords as weak SHA-256 hashes. Fortinet moved to stronger PBKDF2 in versions 7.2.11, 7.4.8, and 7.6.1, but according to Bitsight, existing passwords remain stored as SHA-256 until an administrator logs in again after upgrading. The attackers used a 45-GPU rig to crack them in bulk, offline.

Look closely: there's no magic vulnerability here. Just reused passwords, configurations exposed to the internet, and an upgrade that looked safe but wasn't yet.

As for who's behind it, researchers don't agree. SOCRadar links the campaign to the Lynx/INC ransomware group (active since 2023); Bitsight notes the presence of post-exploitation tools previously associated with state activity. What they agree on: the data is spreading, and anyone who buys it can use it.

Why this is a small-business story too

You might think: "I'm not NATO, I'm not a conglomerate. Who'd bother targeting me?" That is exactly the fatal misconception.

FortiBleed didn't target anyone in particular. It scanned the entire internet automatically and took whatever was left unlocked. In the data, SOCRadar counted 591 government entries across 111 domains, with India accounting for more than 60% of the exposed government bodies. Victims weren't "chosen" because they mattered. They were scooped up because they were exposed.

For most small and mid-sized companies, it's very likely at least one of these is sitting on the internet with a reused password: a router or firewall, a VPN gateway, a website admin panel, a hosting control panel. Attackers don't care how big your company is. They care whether your door is locked.

Five nearly free steps that would have stopped it

The bitterest thing about FortiBleed: every defense needed was cheap, old, and well known. People just didn't do them.

Minimum checklist. Do it today:

  1. Never reuse passwords. Device and admin passwords must be unique and strong. A password leaked somewhere else must not open a door here.
  2. Turn on multi-factor authentication (MFA/2FA) for every admin and VPN account. It's the most effective protection per dollar spent.
  3. Don't expose admin interfaces to the internet. Restrict admin access to your internal network or a trusted IP range.
  4. Update, and verify the update took. Upgrade firmware and software, then check that the fix is actually in effect (as the PBKDF2 lesson above shows, upgraded does not mean safe).
  5. Rotate every credential if your device may have been in the affected population.

On June 18, 2026, CISA (the US cybersecurity agency) issued an alert urging organizations to "take immediate action to harden Fortinet environments," and the UK's NCSC issued a parallel warning. Their guidance, boiled down, is the list above. There's nothing mysterious about it.

What this signals

While the industry chatters about AI hackers and the attacks of the future, the truly big breach of summer 2026 reminds us of an old truth: security isn't something you buy once. It's an operating discipline you keep up every day. Buying a premium firewall and then leaving default passwords on it, exposed to the internet, is like installing a steel door and leaving the key under the mat.

The most memorable irony: the very device you bought to guard your perimeter became the way in. Tools can't save you from bad habits.

For a business owner, the message fits in one sentence: don't fear imaginary future threats; fix the real holes you have now, and most of them cost almost nothing to fix.

When I build and run websites for clients, I tighten these basics by default: no exposed admin panels, two-factor authentication on, regular updates, no reused passwords. If you'd like to check where your website and infrastructure might be leaving the key under the mat, get in touch.

Sources

Related articles