Lead story
FortiBleed: 73,000 Fortinet Credentials Dumped — and Yours Might Be Among Them
A dataset dubbed "FortiBleed" surfaced this week containing what appears to be working VPN credentials for 73,932 Fortinet and FortiGate firewall URLs across organisations worldwide. The list includes names you'd recognise: Oracle, Lenovo, FedEx, and at least one NATO contractor. Researchers at SOCRadar separately confirmed roughly 30,000 actively compromised Fortinet devices. If you manage Fortinet infrastructure and haven't rotated credentials yet, that sentence should have your full attention.
The mechanics matter here. This doesn't appear to be a single new zero-day — it looks more like an aggregated harvest from multiple sources: older CVEs that were patched but whose credentials were never rotated, plus active exploitation of two critical FortiSandbox vulnerabilities (CVE-tracked, CVSS scores in the 9+ range) that Fortinet patched back in April. Multiple security firms have now observed in-the-wild exploitation coming from several independent threat actors, which means it's not a coordinated campaign — it's a free-for-all.
The credential dump is the nastier part. Even organisations that patched quickly may have left working credentials in the wild. Credentials exfiltrated before a patch don't expire with the patch. Anyone holding a valid username/password can still walk through the front door.
Fortinet gear is deeply embedded in Australian enterprise and government networks. The Australian Signals Directorate has previously flagged Fortinet vulnerabilities in its high-priority advisory cycles, and Fortinet sits on the list of approved network appliances across multiple federal and state government procurement frameworks. SOCI Act entities in particular — critical infrastructure operators in energy, water, transport, and comms — should treat this as a first-priority rotation event, not a scheduled maintenance item.
What should you do right now? Rotate all Fortinet VPN credentials immediately, whether or not you believe you were patched. Check your FortiSandbox, FortiGate, and associated device logs for any authentication events from unusual geolocations or off-hours timestamps going back to April. If you're using the same credential sets across multiple devices — a very common operational shortcut — treat this as a full network-wide rotation.
The broader lesson here is one the industry keeps relearning: patching closes the vulnerability, but it doesn't retroactively invalidate credentials that were exfiltrated before the patch landed. For defenders, that gap — between "we patched" and "we're safe" — is exactly where attackers live.
There's also a market signal worth noting. FortiBleed dropped in the same week that three separate FortiSandbox CVEs entered active exploitation. That's not a coincidence — it reflects a sustained, multi-actor focus on Fortinet's product family. If your network boundary runs on Fortinet, this week is the week to audit that assumption.
