Observed Signal · Jun 17, 2026 · Security Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

Massive 'FortiBleed' Campaign Compromises Fortinet Devices

Executive Signal Summary

Two cybersecurity firms, Hudson Rock and SOCRadar, report an ongoing campaign dubbed "FortiBleed" that has compromised tens of thousands of Fortinet firewalls and VPN gateways worldwide. Attackers scan the internet for exposed Fortinet devices and use lists of previously leaked passwords to brute-force access; compromised devices are then used to harvest additional credentials and propagate further intrusions. Hudson Rock found evidence suggesting more than 73,000 unique Fortinet URLs were compromised, while SOCRadar reported over 30,000 affected devices. Reported victims include large enterprises such as Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens and PwC. Affected countries with the highest counts include India, the United States, Taiwan and Mexico. Fortinet responded saying the campaign is a third-party credential-harvesting activity and reflects reshared data and credential brute-forcing rather than a new Fortinet vulnerability.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Widespread compromise of enterprise network appliances used by major global companies risks data exposure, lateral movement, and operational disruption across affected sectors, including firms that support advertising and marketing operations.

SIGNAL RADAR

Track Fortinet Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Hudson Rock reports evidence that more than 73,000 unique Fortinet URLs were compromised.
  • SOCRadar reports the total of hacked Fortinet devices exceeds 30,000.
  • Attackers scan for exposed Fortinet firewalls and VPNs and gain access using previously leaked passwords (credential brute-forcing/credential stuffing).
  • Hudson Rock lists victims including Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens and PwC.
  • Fortinet said the campaign is a third-party credential-harvesting campaign involving reshared data and bruteforcing, not a new vulnerability.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Jun 17, 2026
Original Coverage Title: “Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecurityJul 28, 2026

FortiOS CVE-2025-68686 Symlink Mitigation Bypass

CVE-2025-68686 is an actively exploited FortiOS vulnerability that allows attackers who already have file-system access to bypass symlink persistence mitigations via crafted HTTP requests to the SSL‑VPN web interface. The flaw can expose sensitive files (configurations, credentials, keys) even after firmware upgrades. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026. Affected FortiOS versions include 6.4, 7.0, 7.2, 7.4.0–7.4.6 and 7.6.0–7.6.1; vendor fixes are available in 7.4.7, 7.6.2 or later. Successful exploitation requires a prior file‑system compromise; remediation guidance includes rebuilding devices, removing artifacts, rotating secrets, and restricting SSL‑VPN exposure.

Read assessment
Supply chain securityMay 19, 2026

Supply-chain attack compromises dozens of open-source packages

Cybersecurity researchers reported a large ongoing supply-chain attack that has compromised hundreds of open-source package versions across dozens of projects. StepSecurity and SafeDep warned that attackers hijacked a developer account and pushed more than 630 malicious versions spanning 317 npm packages in roughly 20 minutes. The malicious updates aim to harvest credentials — including from password managers — and to propagate further. Affected projects include Antv (a library associated with Alibaba); JFrog Security said some malicious updates were published via GitHub. Researchers call the campaign “Mini Shai-Hulud”; it follows an earlier wave that compromised the TanStack library and led to the computers of two OpenAI employees being breached. The incident underscores ongoing risks in open-source dependency security and rapid downstream exposure for developers and organizations that consume compromised packages.

Read assessment
CybersecuritySep 22, 2026

Password-Stealing Malware Exposes 1,787 US Water Providers

New research from cybersecurity firm SpyCloud reveals that over a thousand U.S. water and wastewater providers are at risk due to password-stealing malware that compromised employee credentials and session tokens. The firm analyzed over 66,000 public-facing systems registered with the Environmental Protection Agency, identifying 1,787 organizations (nearly 20%) with stolen credentials, and at least 250 with credentials having potential access to operational networks. A case study of an unnamed metering tech provider found one infected device had leaked passwords for 167 utility companies. While this research did not link these exposures to the recent Iran-backed hacks, it underscores the vulnerability of critical infrastructure through infostealer malware and the trade of stolen credentials.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.