Security researchers say the ongoing “FortiBleed” campaign targets Fortinet FortiGate appliances to harvest authentication secrets and steal credentials. Multiple outlets report that the attackers deploy a custom sniffer component to collect credential material from compromised or exposed firewalls, enabling the operation to build large credential sets.
Reports describe FortiBleed as a large-scale, automated credential-harvesting effort. The campaign is assessed to have targeted more than 430,000 FortiGate firewalls globally, with researchers estimating that it identified credential data tied to roughly 110 million credentials. One outlet attributes the activity to an initial access broker operating with financial motivation, while others focus on the technical implementation and the tools left behind.
Analysts say the operation includes steps such as collecting credential lists, checking for exposed services, attempting access through brute-forcing where feasible, and using additional bespoke tooling to advance access. Researchers also describe the attack pipeline as highly automated, and in some cases capable of progressing beyond credential theft. Overall, the coverage emphasizes the scale of the targeting and the presence of attacker-made components used to collect and weaponize credential information.