Fortinet firewalls hit by massive password-stealing attack – around 75,000 users possibly affected


  • Researcher Bob Diachenko Uncovers “FortiBleed”, Massive Archive of 73,932 Fortinet/FortiGate VPN Credentials from Brute-Force and Exploit Campaigns
  • Data included common usernames, emails and passwords for major companies (Chevron, Samsung, Toyota, AT&T, NATO contractor, etc.), with billions of login attempts logged
  • Fortinet says the leak is a redistribution of past events and brute-forced data that encourages password rotation and MFA to minimize risk

A database containing tens of thousands of login credentials for major global companies was found online in one of the major data breach incidents this year.

Security researcher Bob Diachenko posted a new report on LinkedIn saying he discovered an archive of Fortinet and FortiGate VPN credentials numbering 73,932 firewall URLs.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top