La filtración FortiBleed expone credenciales VPN de Fortinet y FortiGate de más de 73.000 dispositivos

FortiBleed leak surfaces tens of thousands of VPN credentials
A newly discovered data leak dubbed “FortiBleed” has exposed what appears to be a large collection of Fortinet and FortiGate VPN credentials tied to 73,932 firewall URLs at organizations around the world.
Security researcher Bob Diachenko said he first found a server containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses and plaintext passwords. Screenshots and details he shared show entries linked to companies including Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec and State Grid, among many others.
“Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action,” Diachenko posted on LinkedIn.
He said one file alone contained 21,634 domain names, spanning a wide range of organizations and including Fortinet itself. The exposed records also included comments listing each target’s industry, revenue and employee count, suggesting the data was organized for attack planning.
Diachenko later said the operation appeared to be run by a Russian-speaking multi-operator threat group that harvested credentials for FortiGate SSL VPN devices. In his account, the attackers carried out about 1.16 billion credential attempts against 320,777 FortiGate targets, along with another 2.1 billion attempts against 163,650 Microsoft SQL Server systems.
He also said the group intercepted SSL VPN authentication hashes, cracked them using a 45-GPU cluster managed through Hashtopolis, and used the recovered credentials to move laterally into internal Active Directory environments.
Diachenko told BleepingComputer he found additional files on the same server, including artifacts, connection strings, tooling, scripts and logs that helped reconstruct the activity.
According to his investigation, multiple organizations in Japan, Taiwan, Vietnam, Iraq and Turkey were fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly stolen.
Threat intelligence company Hudson Rock later published its own analysis after receiving the dataset from Diachenko. It described the collection as one of the largest known troves of compromised Fortinet-related credentials, saying it contains 73,932 unique firewall URLs across 194 countries and affects 21,632 unique domains.
Fortinet said in a statement that it was aware of the reports and that the issue did not stem from a Fortinet product vulnerability.
Fuentes:
Lee más noticias tecnológicas en el Doppler VPN Blog.