You Bought the Firewall to Keep Them Out. It Let Them Listen.

A firewall is the one box a small business is told it cannot operate without — the thing standing between its network and the open internet. For at least 430,000 of them this spring, that box quietly copied every credential that passed through it and shipped the result to a broker working Moscow business hours.

The campaign is called FortiBleed, and the most important fact about it is what the attackers didn't do. They didn't write clever malware. They didn't burn a zero-day. They turned on a feature.

Here's what's confirmed. A Russian-speaking initial-access broker — financially motivated, not state-sponsored — has been running this since February 2026. The tool at the center is a Go-based utility researchers named FortigateSniffer, and it abuses FortiOS's own built-in diagnostic command, diagnose sniffer packet, to passively capture authentication traffic across 24 protocols — RADIUS, Kerberos, NTLM, LDAP, RDP, MS-SQL, MySQL, TACACS+, and more. Once an attacker has admin access to the firewall, they flip on a command FortiGate ships with, and the appliance becomes a wiretap. No malware on disk. Nothing for your antivirus to find. The feature was the weapon.

Sit with the scale. Across credential-harvesting pipelines run on May 31 and June 15, 2026, the operation identified more than 110 million credentials — including 14.8 million RADIUS credentials, 924,000 NTLM hashes, 130,000 Kerberos hashes, and 89 million MySQL tokens. Separately, security researcher Volodymyr "Bob" Diachenko documented a dataset of 73,932 individual FortiGate firewalls with valid administrative and SSL-VPN credentials exposed, across 194 countries and more than 21,600 domains. One number is what they reached for. The other is what they're holding.

And here is the part that should end the "sophisticated nation-state actor" excuse before it starts: the victims weren't Fortune 500s with a security operations center. SOCRadar found the campaign focused on businesses with fewer than 200 employees — roughly 90% with revenue under $100 million — with IT service providers hit hardest, on purpose. Compromise one managed service provider and you inherit a path into every client it touches. The attacker even ranked targets by economic value before spending effort on them, and geofenced the operation to 7 a.m.–6 p.m. Moscow Time. It ran like a job, because it was one.

Two failures own this, and neither is the hacker.

The first is the product. A security appliance ships with a diagnostic command that can passively sniff 24 protocols' worth of credentials, reachable by anyone holding the admin panel. Fortinet did not invent this attack — but this is not the first FortiGate mass-credential story of 2026 either. The appliance has been the soft target for years, and "you should have patched faster" only works as a defense until the same vendor's box is the recurring point of failure. At some point the recurrence is the story.

The second is the arrangement the whole industry is built on: small businesses are sold the appliance and the blame. Buy the firewall — you have to, you'll be told. Then when the firewall is the leak, it's your patch cadence, your password reuse, your management interface left on the public internet, your fault. The box that was marketed as protection becomes the thing that robbed you, and the invoice for the cleanup lands on the people who could least afford the box in the first place.

So if you run a FortiGate, do the unglamorous work today, because it's the only thing between you and someone else's payday: rotate every credential that has ever touched that device — VPN, admin, anything authenticated through it, because the sniffer didn't care which — turn on MFA, pull the management interface off the public internet, and read your authentication logs for logins you can't explain. Some username/password pairs in this campaign showed up across thousands of unrelated IPs, which researchers flagged as possible planted backdoors. Assume you were listened to, not just scanned.

Then ask the question the vendors would rather you didn't: why does a device sold as the front door ship with a wiretap reachable from the admin panel — and why is it always the smallest shop, the two-person IT firm, the people with no leverage and no SOC, who carry the loss?

Credit where it's owed: SOCRadar's "Dismantling FortiBleed" report, SpyCloud, and Volodymyr "Bob" Diachenko did the work of pulling this apart. CISA issued a Fortinet hardening alert on June 18. The receipts are public. The question is whether the next quarter's marketing will admit any of it.

Sources: The Hacker News (Jun 23, 2026); SC Media; Dark Reading; SecurityWeek; SOCRadar, "Dismantling FortiBleed"; SpyCloud; Recorded Future; Volodymyr "Bob" Diachenko (dataset reported Jun 13, 2026); CISA hardening alert (Jun 18, 2026).