Desk live·
ForensicPost
Nation-state/Edge devices/File 26-0602

Tens of Thousands of Firewalls, and the Credentials Were Already Inside

The Fortibleed campaign is reported to have compromised credentials across roughly 75,000 internet-facing FortiGate firewalls. A firewall holds the credentials of everyone permitted through it.

Constructed geometry · not a chart of case data
TargetFortiGate firewalls
ActorUnattributed
D. Kennedy10 min readConfidence: medium2 sources reviewed

The campaign reported as Fortibleed involved mass credential compromise against internet-facing FortiGate firewalls. Reported device counts differ between sources — roughly 75,000 in some accounts, over 86,000 in others — and we give both rather than choosing.

The variance is itself informative. Counting internet-facing devices of a given type is done by scanning, and scan-derived populations depend on methodology, timing and what the scanner could fingerprint. Treat any such figure as an order of magnitude.

A Credential Compromise On A Firewall Is Not A Device Problem

Patching a firewall fixes the firewall. It does not un-disclose the credentials the device held, and those credentials belong to users, not to the appliance.

This is the failure mode organisations most consistently under-handle. The vendor advisory says apply the update. The advisory is correct and insufficient: an organisation that patched promptly and rotated nothing is in the same position it was, with a current firmware version.

Rotation At This Scale Is Genuinely Hard

Rotating every credential that transited a compromised remote-access appliance means every remote worker, every service account using it for site-to-site connectivity, and every integration nobody documented. It produces helpdesk load, breaks automation, and takes weeks.

Which is why it frequently does not happen, and why credentials from campaigns like this surface in intrusions long after the vulnerability is closed. The stolen material has a longer useful life than the flaw that produced it.

How we reported this

Compiled from public reporting, listed below. Affected device counts differ between sources and are given as reported. We have not independently scanned or verified the population. Corrections: corrections@forensicpost.com.

Sources
  1. FortiBleed cracks 86,644 Fortinet firewallsTech Insider
  2. Ransomware gangs attack Palo Alto, Fortinet, Citrix and Check Point VPNsCybersecurity News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary