In mid-June 2026 a credential leak nicknamed FortiBleed put roughly 73,932 Fortinet FortiGate VPN logins - in plaintext - into the open, across 194 countries. It's an enterprise-infrastructure story on the surface, but the way it was assembled is a blunt lesson about everyone's passwords. Here's what happened and what to actually do.
What happened
Security researchers (the discovery is credited to Bob Diachenko) found a dataset containing plaintext usernames, emails and passwords for about 73,932 unique Fortinet FortiGate firewall and SSL-VPN devices, spanning 194 countries and more than 21,000 domains - by some estimates around half of the Fortinet firewalls currently exposed to the internet. The affected organisations reportedly read like a corporate roll-call across major industries. CISA urged affected Fortinet customers to terminate active VPN sessions and reset credentials immediately.
How it was built - recycled, not hacked
This is the important part: the operators didn't crack Fortinet's encryption. According to reporting, they assembled the list from:
- Prior Fortinet breach dumps - credentials exposed in earlier incidents.
- Infostealer malware logs - software that silently harvests passwords saved in browsers and VPN clients on infected machines.
They then automatically tested those credentials against every reachable FortiGate device and logged each success. In plain terms: stolen and reused passwords, recycled at industrial scale. No exotic exploit - just the predictable payoff of credential reuse and malware-harvested logins.

Why this matters even if you've never touched a Fortinet box
Because FortiBleed wasn't really about Fortinet - it was about reused and stolen passwords. The same infostealer logs that fed this list routinely contain logins for personal email, banking, gaming and social accounts. The attack worked because credentials get reused across systems and quietly harvested by malware. That risk is universal.
What to do
The defence is the same at every scale:
- Stop reusing passwords. Every account should have a long, unique password so one leak can't open the others. A password manager makes this realistic instead of impossible to remember.
- Turn on two-factor authentication. With 2FA (an authenticator app or hardware key, ideally - not SMS), a stolen password alone won't get an attacker in.
- Starve the infostealers. Keep your OS and browser updated, avoid pirated software and shady downloads, and don't keep sensitive passwords in plaintext files or unprotected browser stores.
- If you run FortiGate, follow CISA's advice now: end active sessions, reset device credentials, and rotate any of those passwords reused elsewhere.
The takeaway
FortiBleed is one of the largest, most public demonstrations of a boring truth: most "hacks" are just reused and stolen passwords being tried somewhere new. You can't control a vendor's breach, but you can make your own credentials worthless to recycle - unique passwords, 2FA, and an infostealer-resistant setup. That's the whole game.
★ Audit Cure53 2024 · ✓ Plan gratuit · Cross-platform
Lock down your accounts → NordPassStrong unique passwords · breach scanner · free tier→Frequently asked questions
What is FortiBleed?
FortiBleed is the name given to a large credential-exposure campaign disclosed in mid-June 2026 affecting Fortinet FortiGate firewalls and their SSL-VPN gateways. Researchers (the discovery is credited to Bob Diachenko) found a dataset with plaintext usernames, emails and passwords for about 73,932 unique Fortinet devices across 194 countries and 21,000+ domains - by some estimates around half of the Fortinet firewalls currently exposed to the internet. It's an enterprise-infrastructure incident, but the way it was built holds lessons for everyone's passwords.
How did attackers get the credentials?
According to reporting, the operators didn't break Fortinet's encryption. They assembled the list from prior Fortinet breach dumps and from infostealer malware logs - software that silently harvests credentials saved in browsers and VPN clients on infected machines - then automatically tested those credentials against every reachable FortiGate device and recorded each successful login. In other words, it's credential reuse and stolen-password recycling at industrial scale, not a fancy new exploit.
Was my password in the FortiBleed leak?
FortiBleed specifically concerns Fortinet FortiGate/SSL-VPN device credentials, so it mainly affects organisations running those appliances. If your company uses FortiGate, your IT/security team should follow CISA's guidance: terminate active VPN sessions and reset credentials immediately. As an individual, you can't check this dataset directly, but the underlying cause - passwords stolen by infostealers and reused - means the right response is the same hygiene you'd apply after any breach.
What should I do to protect myself?
Three things. First, stop reusing passwords - give every account a long, unique password so one leak can't unlock others (a password manager makes this practical). Second, turn on two-factor authentication, ideally an app or hardware key, so a stolen password alone isn't enough. Third, protect against infostealers: keep your device and browser updated, avoid pirated software and sketchy downloads, and don't save sensitive passwords in plaintext. If you're on an affected FortiGate, reset now and rotate any reused credentials elsewhere.
Why does a firewall leak matter for ordinary passwords?
Because FortiBleed wasn't really about Fortinet - it was about reused and stolen passwords. The same infostealer logs that fed this list also contain logins for personal email, banking and social accounts. The defence is identical at any scale: unique passwords per site, two-factor authentication, and not letting malware harvest credentials from your browser. FortiBleed is a very large, very public reminder of why those habits matter.



