Cybercriminals have breached tens of thousands of Fortinet firewalls and VPNs used by major companies around the world, according to two cybersecurity companies.
This ongoing large-scale hacking campaign, dubbed FortiBleed, does not involve exploiting any unknown vulnerabilities in the targeted devices, but appears to involve more fundamental issues. Companies may never change their firewall passwords or make sure hackers don't know the credentials they use for sensitive systems exposed on the Internet.
In this campaign, hackers first use automated tools to scan the Internet for exposed Fortinet firewalls and VPNs. It then uses a list of known passwords to break into your device. At that point, cybercriminals may steal even more sensitive data from victim companies, cybersecurity firms Hudson Rock and SOCRadar said in a report released this week.
“Once a device is compromised, [the hackers] Use this as a listening post to monitor passing traffic and collect additional credentials as it passes. These newly collected passwords are fed back to the scanner and more devices are compromised. The system automatically feeds the information,” SOCRadar writes.
Hudson Rock said it found evidence suggesting more than 73,000 unique Fortinet URLs were hacked, while SOCRadar said the total number of hacked devices was more than 30,000.
According to Hudson Rock, the hacked companies include Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC.
A Lenovo spokesperson acknowledged TechCrunch's request for comment, but did not receive a response. The other companies did not respond to requests for comment.
According to both Hudson Rock and SOCRadar, the countries with the most affected devices are India, the United States, Taiwan, and Mexico. However, both companies say there are victims all over the world. According to Hudson Rock, the industries most affected include IT services, construction materials, and telecommunications. According to SOCRadar, government agencies are also among the victims. Both cybersecurity companies said the group behind the hacking campaign appears to be Russian-speaking.
Fortinet did not respond to a request for comment.
Hudson Rock and SOCRadar's report is based on the discovery of a list of credentials for Fortinet devices and affiliates. The hacking activity was first reported over the weekend by security researcher Bob Diatchenko. Kevin Beaumont, an independent cybersecurity researcher, said in a blog post Wednesday that his analysis confirmed the data was “legitimate.”
Several hacking campaigns have targeted and compromised Fortinet devices in recent years, typically by exploiting vulnerabilities in those systems. In this case, hackers instead rely on a simpler and less sophisticated attack: compromised passwords.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

