The campaign reported as Fortibleed involved mass credential compromise against internet-facing FortiGate firewalls. Reported device counts differ between sources — roughly 75,000 in some accounts, over 86,000 in others — and we give both rather than choosing.
The variance is itself informative. Counting internet-facing devices of a given type is done by scanning, and scan-derived populations depend on methodology, timing and what the scanner could fingerprint. Treat any such figure as an order of magnitude.
A Credential Compromise On A Firewall Is Not A Device Problem
Patching a firewall fixes the firewall. It does not un-disclose the credentials the device held, and those credentials belong to users, not to the appliance.
This is the failure mode organisations most consistently under-handle. The vendor advisory says apply the update. The advisory is correct and insufficient: an organisation that patched promptly and rotated nothing is in the same position it was, with a current firmware version.
Rotation At This Scale Is Genuinely Hard
Rotating every credential that transited a compromised remote-access appliance means every remote worker, every service account using it for site-to-site connectivity, and every integration nobody documented. It produces helpdesk load, breaks automation, and takes weeks.
Which is why it frequently does not happen, and why credentials from campaigns like this surface in intrusions long after the vulnerability is closed. The stolen material has a longer useful life than the flaw that produced it.
Compiled from public reporting, listed below. Affected device counts differ between sources and are given as reported. We have not independently scanned or verified the population. Corrections: corrections@forensicpost.com.
- FortiBleed cracks 86,644 Fortinet firewallsTech Insider
- Ransomware gangs attack Palo Alto, Fortinet, Citrix and Check Point VPNsCybersecurity News