RESEARCHER UNCOVERS 73,932 FORTINET CREDENTIALS IN DATA LEAK
Security researcher Bob Diachenko discovered an archive containing 73,932 Fortinet and FortiGate VPN credentials exposed online, according to a report posted on LinkedIn. The archive held usernames, email addresses, and passwords in plaintext for major corporations including Chevron, Samsung, Toyota, AT&T, Mercedes-Benz, Comcast, Foxconn and Sinopec. Diachenko named the campaign "FortiBleed" and attributed it to a Russian-speaking threat actor harvesting credentials for FortiGate SSL VPN instances. A NATO defence contractor based in Turkey was among the organisations affected, Diachenko stated.
Analysis of the database revealed the attackers conducted brute-force attempts on a substantial scale, according to Diachenko's findings. The threat actor ran more than 1.1 billion credential attempts against over 320,000 FortiGate instances and 2.1 billion attempts against 160,600 Microsoft SQL Server systems. The attackers also obtained SSL VPN authentication hashes which they subsequently cracked to access Active Directory environments. Diachenko told security outlet BleepingComputer that multiple organisations worldwide experienced full compromise of their systems.
Fortinet responded by characterising the leaked data as a resharing of information from past incidents combined with brute-forced credentials, according to company statements. The firm urged users to rotate passwords and enable multi-factor authentication to minimise risk. Diachenko's discovery represents one of the larger data leak incidents reported this year, exposing the scale of ongoing credential harvesting campaigns against enterprise firewall systems.