Security researchers report that a large set of login credentials for Fortinet FortiGate firewalls and VPN gateways is exposed in a dataset dubbed “FortiBleed.” According to analyses cited by multiple outlets, the material includes plaintext usernames, emails, and passwords associated with 73,932 (about 74,000) unique Fortinet devices across 194 countries, linked to more than 21,000 domains. Researchers say the credentials are contained in configuration-related files connected to firewall and VPN systems.

The dataset is described as the result of credential theft, rather than a newly discovered zero-day vulnerability. One report attributes the compromise to a cybercriminal group that previously stole credentials and then accidentally exposed the data by making it available on a server, where it was later identified. Security researcher Volodymyr “Bob” Diachenko is credited with noticing the exposure and alerting others, after which additional researchers examined the contents.

The reports emphasize that organizations with affected Fortinet devices may have had valid access credentials exposed and could face account misuse if passwords have not been changed.