FortiBleed Leak: A Massive Exposure of Fortinet Credentials
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged Fortinet customers to secure their devices after a massive data leak, dubbed FortiBleed, exposed nearly 74,000 firewall and VPN credentials. This warning comes after threat actors used compromised credentials to target internet-accessible Fortinet devices across government and private-sector organizations worldwide.
According to CISA, FortiBleed involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways. The agency has called on affected FortiGate appliance owners to take immediate action to secure their devices.
Recommended Actions
- Terminate all SSL VPN and administrative sessions
- Reset all VPN and administrative passwords
- Enable phishing-resistant multifactor authentication
- Review logs for signs of unauthorized access or lateral movement
CISA also advised Fortinet customers to store admin credentials using the modern Password-Based Key Derivation Function 2 (PBKDF2) hashing algorithm and to restrict firewall management interfaces from public internet access. Additionally, removing any unauthorized accounts can help reduce the attack surface as much as possible.
The FortiBleed Data Leak
The FortiBleed data leak was uncovered by security researcher Volodymyr Bob Diachenko, who discovered a server containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for 73,932 firewall URLs worldwide. The exposed data also includes each organization's industry, revenue, and employee count, which Diachenko said appeared to be compiled to assist in planning future attacks.
Threat intelligence company Hudson Rock, which analyzed the dataset, described it as one of the largest known collections of compromised Fortinet credentials, spanning 21,632 unique domains and 194 countries. The dataset includes organizations such as Samsung, Mercedes-Benz, Foxconn, Chevron, Comcast, AT&T, and Toyota, along with many government agencies and critical infrastructure operators.
Affected Organizations and Countries
The highest number of affected devices were from India, the United States, Taiwan, Mexico, Turkey, Thailand, Colombia, Malaysia, Chile, and the United Arab Emirates. The leak has significant implications for the security of these organizations and their customers.
Link to Russian-Speaking Threat Group
Diachenko also said that the operation was conducted by a Russian-speaking threat group that allegedly carried out approximately 1.16 billion credential attempts against more than 320,000 FortiGate targets to intercept SSL VPN authentication hashes. The source of the configuration data remains unknown.
Cybersecurity expert Kevin Beaumont has independently confirmed the authenticity of some credentials and noted that most affected devices remain online. The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data, Beaumont said, adding that the leaked data appears to have originated from Fortinet configuration files.
Free FortiBleed Lookup Tool
Hudson Rock has created a free FortiBleed lookup tool to help organizations check whether they are affected. This tool can be used to determine if an organization's credentials have been exposed in the leak.
Related Vulnerabilities and Exploits
On Monday, threat intelligence company Defused reported that several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform are now exploited in attacks. In total, CISA tracks 26 Fortinet security flaws that have been exploited in the wild in recent years, 13 of which were abused in ransomware attacks.
Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper to learn more about protecting your organization from cyber threats.
Source: BleepingComputer