An ongoing hacking campaign dubbed FortiBleed has compromised tens of thousands of Fortinet firewalls and VPNs used by major companies worldwide, according to cybersecurity firms Hudson Rock and SOCRadar, who published their findings in June 2026.
Hudson Rock identified more than 73,000 unique Fortinet URLs as compromised, while SOCRadar put the figure at more than 30,000 devices. Among the affected companies named by Hudson Rock are Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC. Government agencies are also among the victims, according to SOCRadar.
The attack does not exploit any unknown software vulnerability. Instead, hackers are using automated tools to scan the internet for exposed Fortinet devices, then breaking in using lists of previously known, leaked passwords. Once inside a device, attackers use it to monitor passing network traffic and harvest additional credentials, which are fed back into the scanning system to compromise further devices. “The system feeds itself,” SOCRadar wrote in its report.
The countries with the most affected devices are India, the United States, Taiwan, and Mexico, though both firms report victims across the globe. The most impacted industries are IT services, construction materials, and telecommunications, per Hudson Rock. Both companies said the group behind the campaign appears to be Russian-speaking.
The campaign was first reported by security researcher Bob Diachenko. Independent researcher Kevin Beaumont subsequently analyzed the data and confirmed it “is legit.”
The root cause appears to be basic credential hygiene: companies may not be changing default or previously exposed passwords on internet-facing firewall systems. Fortinet did not respond to a request for comment, and most named companies also did not respond. A Lenovo spokesperson acknowledged the inquiry but provided no statement.
The findings suggest that reused or unrotated credentials on publicly exposed network devices may leave organizations vulnerable even without any new software flaw being exploited.
Source: TechCrunch