What Happened
On 17 June 2026, security researcher Bob Diachenko discovered an exposed server containing what appears to be a large collection of Fortinet and FortiGate VPN credentials — including usernames, email addresses, and plaintext passwords — for 73,932 firewall URLs across 194 countries. The dataset was published by threat intelligence firm Hudson Rock, which described it as one of the largest known troves of compromised Fortinet-related credentials ever identified.
Independent cybersecurity researcher Kevin Beaumont reviewed portions of the data and confirmed that some credentials are authentic. "The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data," Beaumont wrote in his published analysis.
Beaumont also noted that the affected IP addresses are different from those in the 2025 Belsen Group Fortinet leak — this is a separate, more recent, and larger collection. The exposed dataset covers approximately half of all internet-accessible Fortinet firewalls globally.
How the Credentials Were Obtained
Based on Diachenko's analysis of additional files inadvertently left exposed on the same server, the operation appears to have been conducted by a Russian-speaking multi-operator threat group. The attackers allegedly:
- Conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets
- Intercepted SSL VPN authentication hashes and cracked them using a 45-GPU cluster managed through Hashtopolis
- Used recovered credentials to move laterally into internal Active Directory environments
- Conducted an additional 2.1 billion attempts against 163,650 Microsoft SQL Server systems
Beaumont's review further indicates the data was likely extracted from exported Fortinet device configurations, because it contains information — including email addresses — that is only accessible through device config exports, not through authentication attempts alone. This suggests the attackers gained administrative access to affected devices, not merely credential-level access.
The exposed data also included detailed notes on each organisation's industry sector, revenue, and headcount — strongly suggesting the dataset was assembled to facilitate targeted follow-on attacks, not opportunistic credential resale.
South African Organisations in the Dataset
Threat intelligence firm Hudson Rock has identified credential records tied to Fortinet VPN devices associated with the following South African organisations. Appearance in this dataset indicates that credentials associated with that organisation's network are present in publicly-accessible threat intelligence databases. Given that independent researchers have confirmed a significant portion of the credentials are currently valid and active, affected organisations should treat this as urgent.
Affected organisations by sector
| Organisation | Sector | Size | Records |
|---|---|---|---|
| eoh-ns.co.za | IT Services | 201–500 employees | 224 |
| reflex.co.za | Office Furniture | 51–200 employees | 51 |
| uoas.co.za | Education | 51–200 employees | 25 |
| bcx.co.za | IT Services | 1001–5000 employees | 21 |
| actom.co.za | Electrical Engineering | 201–500 employees | 14 |
| emid.co.za | IT Services | 51–200 employees | 9 |
| westcoastcollege.co.za | Education | 51–200 employees | 7 |
| vodacom.co.za | Telecommunications | 10,000+ employees | 5 |
| is.co.za | Media & Publishing | 201–500 employees | 5 |
| b2e.co.za | Recruitment | 51–200 employees | 5 |
| forbtech.co.za | Technology Solutions | 11–50 employees | 5 |
| networkassociates.co.za | IT Services | 51–200 employees | 4 |
| fifthfactor.co.za | Management Consulting | 11–50 employees | 3 |
| rohloffgroup.co.za | Manufacturing | 51–200 employees | 3 |
| itecgroup.co.za | IT Services | 51–200 employees | 3 |
| mweb.co.za | Telecommunications | 1001–5000 employees | 2 |
| wilderness.co.za | Tourism | 51–200 employees | 2 |
| avisbudget.co.za | Car Rental | 1001–5000 employees | 1 |
| dninvest.co.za | Investment Services | 11–50 employees | 1 |
| + 30 additional organisations (1–2 records each) across retail, financial services, agriculture, healthcare, and government sectors. | |||
What This Means for Your Business
The critical difference between this event and a typical vulnerability disclosure is that the credentials being discussed are not theoretical or potentially-compromised — independent security researchers have confirmed that a significant portion are currently active and valid. An attacker holding a working VPN credential for your organisation's FortiGate device can authenticate as a legitimate remote user. There are no failed login alerts, no anomalous traffic signatures, and no obvious signs of intrusion at the point of entry.
The configuration-level data in this dataset — if Beaumont's analysis is correct — also means attackers have far more than just a username and password. They may have a detailed map of your VPN configuration, network topology, and user directory. This significantly reduces the reconnaissance effort required for a follow-on attack.
Three questions determine your current risk level:
Are your FortiGate VPN credentials from the past several years still valid? If any user or service account with VPN access has not had its password changed recently, that credential may be in this dataset. Rotation is the only mitigation.
Is Multi-Factor Authentication enforced on VPN access? MFA does not eliminate the risk from credential theft but dramatically increases the effort required to exploit it. If MFA is not enforced today, enabling it is the single highest-value control you can implement this week.
Do you have visibility into authentication events on your FortiGate device? Without active monitoring of login events, a successful attacker entry using valid credentials will look identical to a legitimate remote login. Anomaly detection on authentication — unusual hours, unexpected geographies, unfamiliar IP addresses — is the most likely way this type of intrusion would be detected.
Immediate Steps to Take Now
- Check the Hudson Rock lookup tool. Hudson Rock has published a free FortiBleed lookup at hudsonrock.com/fortinet where you can check whether your organisation's domain appears in the dataset.
- Rotate all FortiGate VPN and admin credentials immediately. All accounts with VPN or administrative access to FortiGate devices should have their passwords reset without delay. Do not scope this only to accounts you think might be affected — rotate all of them.
- Rotate any Active Directory credentials used on or near the VPN. If the attackers moved laterally into AD environments as reported, any service accounts or admin credentials associated with systems that authenticate through the VPN should also be rotated.
- Review FortiGate authentication logs now. Look for successful VPN logins at unusual hours, from unexpected geographic locations, or from IP ranges associated with VPN/proxy services and hosting providers. Pay particular attention to any access in the past 90 days.
- Enforce MFA on all VPN access immediately. If this is not already in place, it should be treated as an emergency control gap and closed this week.
- Verify FortiOS firmware is current. While Fortinet states this is not linked to a new vulnerability, ensuring firmware is up to date eliminates any residual exposure from previously disclosed vulnerabilities and is standard practice.
The Broader Picture
The South African organisations appearing in this dataset span virtually every sector of the economy — from telecommunications giants and IT service providers to educational institutions and investment firms. This reflects the indiscriminate, automated nature of the campaign: every reachable FortiGate device on the internet was targeted regardless of the size or profile of the organisation behind it.
This dataset also represents only what has been identified in publicly-monitored threat intelligence sources. The South African impact is almost certainly broader than the 50-odd domains appearing in the Hudson Rock data, particularly for organisations whose devices may not be indexed by the scanning infrastructure used in this analysis.
PulseDefend is available to assist affected organisations with credential exposure assessment, FortiGate log review, and emergency incident response engagement. If you believe your organisation may be affected and want an expert assessment, contact our team directly — and if you are dealing with an active breach, call immediately.
Is your organisation in the dataset?
PulseDefend can run a credential exposure check, review FortiGate authentication logs, and provide emergency IR triage — typically within 48 hours of engagement. Active breach? Call +27 65 999 3305 directly.