WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

86,644 Firewalls in 194 Countries Breached With Stolen Passwords

Image showing a pile of rustic and shiny padlocks, symbolizing security.
Illustrative photo.Photo by Goszton on Pexels

What happened

Attackers continue to scan exposed Fortinet firewalls (a barrier that decides which network traffic may pass) using previously obtained credentials, and some affected organizations have been locked out of their own systems. The open directory revealed a mature, multi-stage campaign run as an initial access broker operation.

Secret Service (USSS) have issued a joint cybersecurity advisory warning organizations about FortiBleed, an active global credential-compromise campaign targeting internet-facing Fortinet FortiGate (enterprise firewalls) firewalls and SSL (the encryption that secures a connection to a website) VPN (a service that routes a connection through another network) gateways. The advisory, published on October 6, 2026, cites SOCRadar data verifying more than 86,644 compromised devices across 194 countries.

According to the advisory, the campaign exploits reused or leaked credentials and legacy SHA-256 password storage, allowing threat actors (the person or group behind an attack) to harvest and crack authentication data at scale. How the FortiBleed Attack Chain Works The operation's internal workflow came to light after the threat actors unintentionally exposed their own backend server.

Sources & evidence