🤚 The Open-Palm Credential Catastrophe
Security researcher Bob Diachenko has discovered what can only be described as the corporate world’s worst password spreadsheet: a server containing valid Fortinet and FortiGate VPN credentials — usernames, email addresses, and plaintext passwords — for 73,932 unique firewall URLs across 194 countries. The dataset reads like a Fortune 500 attendance sheet: Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Siemens, Lenovo, PwC, Accenture, and Oracle all appear in the collection, alongside numerous government agencies whose names you’d prefer not to see next to the phrase “plaintext passwords.”
The operation, attributed to a Russian-speaking multi-operator threat group, was not subtle. The attackers:
- Executed an estimated 1.16 billion credential-based attempts against 320,777 FortiGate targets
- Ran a parallel 2.1 billion brute-force attempts against 163,650 Microsoft SQL Server systems, because why compromise one attack surface when you can have two
- Cracked captured SSL VPN authentication hashes using a 45-GPU cluster managed through Hashtopolis
- Affected approximately half of all internet-accessible Fortinet firewalls
The geographic hotspots include India, the United States, Taiwan, Mexico, Turkey, Thailand, Colombia, Malaysia, Chile, and the UAE — essentially every country where someone once said “just expose the management interface, it’ll be fine.”
👐 The Two-Handed Reckoning
Here is where it gets philosophically painful: FortiBleed is not a zero-day. There is no CVE. There is no newly discovered vulnerability. Fortinet confirmed that the credentials came from “previous incidents” and “brute-force attacks” — which is corporate for “these passwords were already stolen, and nobody changed them.”
The attackers didn’t need to discover a flaw in the fabric of cryptography. They needed a list of old passwords and the patience to try 1.16 billion of them. The 45-GPU cracking cluster sounds impressive until you realize it was cracking passwords that organizations should have rotated after the last time they were compromised. The metadata in the leaked dataset — including industry classifications, revenue figures, and employee counts — suggests the operators weren’t just collecting credentials for sport. They were building a targeting menu, sorted by how much the victim could afford to pay.
The affected industries read like a syllabus for “Critical Infrastructure 101”: telecommunications, IT services, financial services, government, healthcare, education, and manufacturing. The majority of compromised devices were running relatively recent FortiOS versions, which means the software was up to date. The passwords were not.
🌿 The Gentle Awakening
There is something almost meditative about a security incident that doesn’t involve a zero-day, a nation-state exploit chain, or a novel attack technique. FortiBleed is the cybersecurity equivalent of someone walking through an unlocked door, finding the safe combination taped to the monitor, and photographing the contents while the security guard was on a break he started in 2023.
We have spent billions on next-generation firewalls, zero-trust architectures, AI-powered threat detection, and extended detection and response platforms. And yet, approximately 75,000 enterprise firewalls — the devices whose entire job description is protecting networks — were compromised because their credentials were reused, never rotated, or brute-forced with the computational equivalent of a mid-range gaming PC farm.
The researchers noted that most of the cracked passwords were “long, complex passwords” that would ordinarily be difficult to break. But ordinarily doesn’t account for a dedicated operation with industrial cracking infrastructure and all the time in the world. Complexity without rotation is just a longer string that takes a longer weekend.
👑 The Gold-Leaf Damage Assessment
If your organization runs Fortinet hardware — and statistically, there’s a coin-flip chance it does — the to-do list is immediate and non-negotiable:
- Rotate every credential on your FortiGate VPN and administrative interfaces. Yes, all of them. Yes, right now.
- Enforce multi-factor authentication on every management interface that faces the internet, which ideally should be none of them
- Audit your gateway logs for suspicious activity dating back months
- Use Hudson Rock’s free FortiBleed lookup tool to check if your organization appears in the dataset
- Stop exposing management interfaces to the internet, a recommendation that has been offered approximately four billion times and ignored approximately four billion times
The threat group conducted 3.26 billion authentication attempts across two platforms. That’s not a scan. That’s not reconnaissance. That’s an industrial harvesting operation with a business plan, a GPU budget, and better operational discipline than most of the organizations it compromised.
“The firewall’s credentials were in plaintext, the management interface was on the internet, and the password hadn’t been changed since the previous breach. Other than that, the security posture was excellent.” — The Slap of Wisdom Perimeter Defense Bureau, rotating its own credentials for the third time this paragraph