Fortinet Firewalls Compromised in Global Credential Hacking Campaign

Fortinet firewalls have been compromised in a global credential hacking campaign, affecting numerous prominent organizations.

Security researchers have identified a large-scale credential compromise campaign targeting FTNT FortiGate firewalls, dubbed FortiBleed, that has affected an estimated 75,000 internet-facing devices across 194 countries. Threat actors systematically collected configuration files from exposed FortiGate appliances and cracked administrator credential hashes stored using legacy SHA-256 mechanisms in older FortiOS versions. The campaign is attributed to a Russian-speaking cybercriminal group operating highly automated tooling that allowed large-scale collection, processing, and cracking of credential material in a compressed timeframe.

The scope of the attack is significant. The leaked dataset reportedly contains 73,932 unique FortiGate device URLs tied to more than 21,000 affected domains, with the highest concentrations of compromised devices in India, the United States, and Mexico. Among the enterprises identified in exposure reports: Samsung, Oracle, Foxconn, Siemens, Comcast, PwC, Accenture, Lenovo, Chevron, AT&T, and Mercedes-Benz. The United Kingdom's National Cyber Security Centre issued guidance for potentially affected organizations following the campaign's public disclosure.

Fortinet's response has centered on a firmware-level fix rather than a traditional patch for an exploited vulnerability: the company introduced PBKDF2-based password hashing in FortiOS 7.2.11, 7.4.8, and 7.6.1, replacing the weaker SHA-256 scheme that made credential cracking feasible. Organizations running affected older firmware versions are advised to upgrade immediately and require all administrators to log in post-upgrade to trigger re-encryption of stored credentials. Fortinet also recommends enabling the "login-lockout-upon-weaker-encryption" setting in FortiOS v7.2.x and v7.4.x to remove legacy hashes proactively.

For FTNT investors, the incident arrives at a sensitive time. The enterprise cybersecurity market has been increasingly competitive, with customers scrutinizing vendor security posture as part of procurement decisions. A breach at this scale -- where the vendor's own products are the attack surface -- could slow deal cycles and accelerate customer reviews of multi-vendor architectures. That said, Fortinet separately surpassed one million people trained through its cybersecurity education programs, signaling continued investment in the security community and brand trust. The company's ability to deploy a firmware-based mitigation without an emergency patch may also suggest the vulnerability class was a configuration and key-management issue rather than an exploitable code flaw, which could limit long-term reputational damage if the firmware fix is adopted quickly.

Powered by SentiSense - Intelligent Market Analysis