⚠ Active Threat — Immediate Action Required This is not a historical incident. The FortiBleed dataset was discovered on 17 June 2026 and contains credentials reported to be currently active and valid. Affected organisations should treat this as an active threat and rotate credentials immediately. Do not wait for a scheduled maintenance window.

What Happened

On 17 June 2026, security researcher Bob Diachenko discovered an exposed server containing what appears to be a large collection of Fortinet and FortiGate VPN credentials — including usernames, email addresses, and plaintext passwords — for 73,932 firewall URLs across 194 countries. The dataset was published by threat intelligence firm Hudson Rock, which described it as one of the largest known troves of compromised Fortinet-related credentials ever identified.

Independent cybersecurity researcher Kevin Beaumont reviewed portions of the data and confirmed that some credentials are authentic. "The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data," Beaumont wrote in his published analysis.

Beaumont also noted that the affected IP addresses are different from those in the 2025 Belsen Group Fortinet leak — this is a separate, more recent, and larger collection. The exposed dataset covers approximately half of all internet-accessible Fortinet firewalls globally.

How the Credentials Were Obtained

Based on Diachenko's analysis of additional files inadvertently left exposed on the same server, the operation appears to have been conducted by a Russian-speaking multi-operator threat group. The attackers allegedly:

Beaumont's review further indicates the data was likely extracted from exported Fortinet device configurations, because it contains information — including email addresses — that is only accessible through device config exports, not through authentication attempts alone. This suggests the attackers gained administrative access to affected devices, not merely credential-level access.

The exposed data also included detailed notes on each organisation's industry sector, revenue, and headcount — strongly suggesting the dataset was assembled to facilitate targeted follow-on attacks, not opportunistic credential resale.

Fortinet's Position Fortinet told BleepingComputer that its investigation indicates the credentials were obtained through previous incidents and brute-force attacks, and that this is not linked to any newly disclosed vulnerability or security advisory. Fortinet stated that organisations following routine best practices — including regularly refreshing credentials — "face minimal risk." The origin of the configuration data extraction remains independently unconfirmed.

South African Organisations in the Dataset

Threat intelligence firm Hudson Rock has identified credential records tied to Fortinet VPN devices associated with the following South African organisations. Appearance in this dataset indicates that credentials associated with that organisation's network are present in publicly-accessible threat intelligence databases. Given that independent researchers have confirmed a significant portion of the credentials are currently valid and active, affected organisations should treat this as urgent.

Affected organisations by sector

OrganisationSectorSizeRecords
eoh-ns.co.zaIT Services201–500 employees224
reflex.co.zaOffice Furniture51–200 employees51
uoas.co.zaEducation51–200 employees25
bcx.co.zaIT Services1001–5000 employees21
actom.co.zaElectrical Engineering201–500 employees14
emid.co.zaIT Services51–200 employees9
westcoastcollege.co.zaEducation51–200 employees7
vodacom.co.zaTelecommunications10,000+ employees5
is.co.zaMedia & Publishing201–500 employees5
b2e.co.zaRecruitment51–200 employees5
forbtech.co.zaTechnology Solutions11–50 employees5
networkassociates.co.zaIT Services51–200 employees4
fifthfactor.co.zaManagement Consulting11–50 employees3
rohloffgroup.co.zaManufacturing51–200 employees3
itecgroup.co.zaIT Services51–200 employees3
mweb.co.zaTelecommunications1001–5000 employees2
wilderness.co.zaTourism51–200 employees2
avisbudget.co.zaCar Rental1001–5000 employees1
dninvest.co.zaInvestment Services11–50 employees1
+ 30 additional organisations (1–2 records each) across retail, financial services, agriculture, healthcare, and government sectors.

What This Means for Your Business

The critical difference between this event and a typical vulnerability disclosure is that the credentials being discussed are not theoretical or potentially-compromised — independent security researchers have confirmed that a significant portion are currently active and valid. An attacker holding a working VPN credential for your organisation's FortiGate device can authenticate as a legitimate remote user. There are no failed login alerts, no anomalous traffic signatures, and no obvious signs of intrusion at the point of entry.

The configuration-level data in this dataset — if Beaumont's analysis is correct — also means attackers have far more than just a username and password. They may have a detailed map of your VPN configuration, network topology, and user directory. This significantly reduces the reconnaissance effort required for a follow-on attack.

Three questions determine your current risk level:

Are your FortiGate VPN credentials from the past several years still valid? If any user or service account with VPN access has not had its password changed recently, that credential may be in this dataset. Rotation is the only mitigation.

Is Multi-Factor Authentication enforced on VPN access? MFA does not eliminate the risk from credential theft but dramatically increases the effort required to exploit it. If MFA is not enforced today, enabling it is the single highest-value control you can implement this week.

Do you have visibility into authentication events on your FortiGate device? Without active monitoring of login events, a successful attacker entry using valid credentials will look identical to a legitimate remote login. Anomaly detection on authentication — unusual hours, unexpected geographies, unfamiliar IP addresses — is the most likely way this type of intrusion would be detected.

Immediate Steps to Take Now

POPIA Notification Obligation If your organisation holds personal information about South African residents — employees, customers, or partners — and there are reasonable grounds to believe that credentials providing access to systems holding that information have been compromised, POPIA Section 22 imposes a notification obligation to the Information Regulator and, where applicable, affected data subjects. This assessment should involve your legal counsel and a qualified incident response team who can determine the scope of any actual access that may have occurred.

The Broader Picture

The South African organisations appearing in this dataset span virtually every sector of the economy — from telecommunications giants and IT service providers to educational institutions and investment firms. This reflects the indiscriminate, automated nature of the campaign: every reachable FortiGate device on the internet was targeted regardless of the size or profile of the organisation behind it.

This dataset also represents only what has been identified in publicly-monitored threat intelligence sources. The South African impact is almost certainly broader than the 50-odd domains appearing in the Hudson Rock data, particularly for organisations whose devices may not be indexed by the scanning infrastructure used in this analysis.

PulseDefend is available to assist affected organisations with credential exposure assessment, FortiGate log review, and emergency incident response engagement. If you believe your organisation may be affected and want an expert assessment, contact our team directly — and if you are dealing with an active breach, call immediately.

Is your organisation in the dataset?

PulseDefend can run a credential exposure check, review FortiGate authentication logs, and provide emergency IR triage — typically within 48 hours of engagement. Active breach? Call +27 65 999 3305 directly.

Talk to Our Team Our IR Capability
Sources & Disclaimer: This article draws on reporting by BleepingComputer (Lawrence Abrams, 17 June 2026), independent analysis by Kevin Beaumont (doublepulsar.com), and Hudson Rock's published FortiBleed dataset analysis (hudsonrock.com). The South African domain list is sourced from Hudson Rock's publicly available threat intelligence data. Appearance in this dataset indicates the presence of credential records in monitored threat intelligence databases and does not constitute confirmation of a successful breach, unauthorised access, or ongoing compromise of any listed organisation. Fortinet has stated the collection relates to previous incidents and brute-force activity rather than a new vulnerability. PulseDefend has not independently verified the status of any listed organisation's systems. This article is published for informational and awareness purposes only.