Widespread “FortiBleed” Credential Exposure Campaign Affects Fortinet Firewalls and VPN Gateways
Created: Thursday, June 18, 2026 - 16:18
Categories:
(TLP:CLEAR) ACTION MAY BE REQUIRED for utilities using Fortinet FortiGate firewalls, SSL VPN, or VPN gateway services. Utilities that outsource technology support may need to consult their service providers for assistance with investigation and remediation actions.
Recent public reporting and government alerts describe a widespread malicious campaign, dubbed “FortiBleed,” involving exposed credentials affecting Fortinet firewalls and VPN gateways. The exposed data includes Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords, associated with tens of thousands of Fortinet firewall URLs worldwide…
