FortiBleed campaign used custom FortiGate sniffer to steal credentials
What happened
SOCRadar reports a large FortiBleed campaign that used a custom FortiGate sniffer to harvest authentication secrets from compromised firewalls. The operation targeted hundreds of thousands of FortiGate devices and produced offline cracking files using rented enterprise GPUs, making stolen credentials practical to exploit. Watch supplier advisories and your managed-firewall configurations for evidence of abuse and required mitigations
Why the category manager should care
Prioritize verifying firewall configurations, patching, and admin access controls with suppliers because this exploit leverages legitimate device functions to capture credentials
Key facts
- Operation targeted more than 430,000 FortiGate firewalls worldwide
- Credential collections tied to 80,000+ firewall URLs were reported
- Attacker rented 36 enterprise-class GPUs for offline password cracking