Dubbed FortiBleed, the exploit harvested administrator credentials from Fortinet FortiGate firewalls and VPN gateways, giving attackers legitimate access to affected devices.
The attackers used stolen administrator access and a custom tool called FortigateSniffer to capture authentication traffic moving through Fortinet devices. That traffic included credentials and password hashes that could be used to move deeper into affected networks.
That makes FortiBleed more serious than a leaked password list. The attackers were not only collecting old credentials. They were using firewall-level access to harvest new ones from live environments.
How FortiBleed escalated
SOCRadar reported that the attack targeted more than 430,000 FortiGate firewalls worldwide. Its researchers said the operation harvested more than 110 million credentials, confirmed administrator-level access on 409 targets, and completed the full attack chain on 354. That chain included VPN compromise, access to domain controllers, and domain administrator privileges.
The case developed further on July 2, when SOCRadar linked FortiBleed-derived access to INC Ransom and Lynx ransomware operations. Researchers reported at least 12 ransomware deployments connected to the campaign, with hundreds of endpoints encrypted across affected organizations.
That is the point at which FortiBleed stops being a firewall-exposure story and becomes an infrastructure-access story.
Why maritime and energy operators are exposed
Cydome’s maritime cybersecurity team found FortiBleed data tied to hundreds of maritime organizations, including shipowners, ports, shipyards, offshore service providers, and companies connected to the energy sector. Cydome reported more than 86,000 confirmed working Fortinet administrator credentials across 194 countries in the maritime-related dataset it examined.
Those figures describe different parts of the same problem. SOCRadar’s reporting describes the broader attacker infrastructure and campaign scale. Cydome’s reporting shows how that exposure reaches maritime, energy, and other critical infrastructure operators.
That distinction matters in critical infrastructure because Fortinet devices often sit at the boundary between corporate IT, remote access, vendor maintenance, satellite communications, and operational technology. Administrative control of the firewall is not just control of one appliance. It can provide access to the systems behind it.
Why patching is not enough
The operational failure is not that every affected organization failed to patch. The failure is treating patching as the end of recovery.
A firmware update can close the software condition that allowed access. It does not invalidate credentials already stolen from the device. It does not terminate active sessions, remove unauthorized administrator accounts, rebuild trust in VPN access, or prove that routing and security policies were not changed before the patch was applied.
Cydome’s findings point to the same problem at the configuration level. The company reported that 87% of affected Fortinet devices still had internet-facing management interfaces exposed, while 63% of harvested credentials were tied to default or built-in administrator accounts. Those are ordinary operating decisions that become high-impact failures once credentials leak.
Technical considerations for FortiBleed exposure
FortiBleed represents a shift in incident response, moving from a simple patch management task to a broader credential recovery event. Because this campaign allows attackers to establish persistence that survives a firmware update, industry guidance from bodies like CISA and the NCSC highlights that patching is only the initial step.
Technical teams are currently prioritizing the following recovery vectors:
- Active session termination: Cutting off ongoing unauthorized access that remains active after patching.
- Full credential rotation: Changing all administrator passwords and rotating hashes to mitigate the impact of compromised credentials.
- MFA enforcement: Implementing or strengthening Multi-Factor Authentication to limit the utility of any stolen credentials.
- Administrative account auditing: Identifying and removing unauthorized users, renamed accounts, or “backdoor” accounts created during the compromise.
- Configuration and routing validation: Auditing VPN settings, firewall policies, and routing rules to ensure no persistent access paths were planted prior to the patch.
Once an attacker gains control of an edge device, updating firmware may not be sufficient. A patched firewall with stolen administrator credentials can leave the door open. Industry consensus indicates that infrastructure is generally only secure once the device, the account structure, and the management plane are fully verified.
The UK National Cyber Security Centre (NCSC) has advised organizations to investigate signs of compromise, review administrator accounts, and consider rebuilding affected devices if administrative control cannot be fully verified. This reflects the reality that once an attacker has successfully controlled an edge device, changing passwords may not remove persistence established elsewhere in the network.
FortiBleed illustrates where recovery often breaks down: teams patch the device because the vulnerability is visible, but may delay credential recovery due to operational constraints. Attackers frequently exploit this gap. Ultimately, a patched firewall with stolen administrative credentials remains an active access path, and security is only restored when the entire management plane is re-trusted.ain.
Sources
- CISA: CISA urges hardening Fortinet devices after reports of credential exposure
- SOCRadar: SOCRadar links FortiBleed campaign to INC and Lynx ransomware operations
- Cydome: FortiBleed incident exposes admin access of shipping companies, ports and other maritime operations
- Fortinet PSIRT: Analysis of reported credential compromise of FortiGate devices
- UK National Cyber Security Centre: Advice following global targeting of Fortinet firewalls and VPN gateways
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
