A coordinated FortiBleed campaign used leaked and weakly‑hashed Fortinet admin credentials to take control of 86,644 firewalls across 194 countries. The breach underscores the need for strong privileged‑access controls and continuous audit evidence for compliance readiness.
ADTP Breach Watch· October 7, 2026· Security Affairs
Attackers scanned the Internet for exposed FortiGate SSL‑VPN portals, then performed credential‑stuffing and GPU‑accelerated hash cracking to obtain clear‑text admin passwords. Compromised accounts were used to lock out legitimate admins, create new privileged accounts, and move laterally within victim networks.
Why it matters for trust and compliance
The incident illustrates why continuous monitoring of privileged credentials and immutable logging of admin activity are essential control objectives for audit readiness across multiple frameworks.
Demonstrates the need for real‑time privileged‑access monitoring and evidence collection.
Supports audit readiness by proving that credential‑rotation and MFA policies are enforced.