Skip to main content

Sensitive Inter-Agency Coordination Data Concentrated in Commercial Collaboration Platforms Produces Single-Breach, Multi-Agency Exposure at Scale

SUBJECT: DHS Inter-Agency Coordination Network Breached STATUS: CISA Advisory AUDIENCE: Government, Defense, Critical Infrastructure Security Leads

Jul 15, 2026

·

Blog

·

Secure Communications

CISA issued an emergency hardening alert on June 18, 2026, after a credential harvesting campaign dubbed FortiBleed exposed valid administrator and VPN credentials for tens of thousands of internet-facing Fortinet firewalls across government and private sector organizations worldwide.1 No new vulnerability was exploited.2 The attackers used stolen credentials, brute force, and exposed management interfaces.

What FortiBleed Is — and Why It Is Different

On June 13, 2026, security researcher Volodymyr Diachenko discovered an open server containing valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for tens of thousands of organizations.5 Security researcher Kevin Beaumont and Hudson Rock independently confirmed the dataset.5 By June 19, the confirmed device count had reached approximately 86,644 unique devices across 194 countries, representing roughly half of all internet-facing Fortinet firewalls.6

FortiBleed is not a CVE story. There is no patch that closes it. The attackers harvested credentials through a combination of exposed management surfaces, brute-force attacks, credential material recovered from exported Fortinet configuration files, and GPU-based offline password cracking against legacy hash formats. Fortinet's own assessment describes the activity as threat actors reusing credentials from previous incidents and brute-forcing devices with weak password hygiene and no MFA.2

CISA Alert — June 18, 2026
CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways.1

The dataset is structured as a sales catalog. Each entry includes the target organization's industry, revenue, employee count, and country.4 It was not assembled for personal use. It was assembled for sale or coordinated deployment across a criminal team.4-5 An attacker with these credentials can log in remotely, access the firewall and therefore the network behind it, change security settings, and use the device as a persistent foothold.

Exposure Analysis: What the Attackers Had and What They Could Do With It

Companies appearing in the dataset including many confirmed by Hudson Rock, were Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators.⁴ The dataset spans 21,632 unique domains.⁵ The breadth is not incidental — it is the product.

Access Type
What the Attacker Controls
Detection Difficulty
Firewall administrator credentials
Full device configuration access: routing, filtering rules, logging settings, VPN policies. Can disable security controls, create persistence, and cover tracks.
High — valid credentials produce no authentication alerts
VPN gateway credentials
Remote access to internal network as an authenticated user. Bypasses perimeter controls entirely.
High — traffic appears as legitimate remote worker session
Exported configuration files
Complete network topology, internal IP ranges, policy logic, and credential hashes for offline cracking.
N/A — data already exfiltrated before detection
Legacy PBKDF1 password hashes
Offline GPU cracking yields plaintext passwords, which are then reused across other systems and platforms.
None — cracking occurs entirely off-network
Lateral movement foothold
Once inside the network via VPN or management interface, attacker pivots to internal systems, domain controllers, and data repositories.
Low — post-exploitation activity mimics normal user behavior

A credential campaign targeting half the internet-facing Fortinet fleet does not trigger exploit signatures, does not deploy malware at the entry point, and does not announce itself in any way that a perimeter block or intrusion detection system is designed to catch. The detection problem is precisely that the abuse resembles legitimate administrative activity: valid credentials, valid usernames, successful authentication.

Root Cause: Three Design Decisions That Made This Possible at Scale

FortiBleed is not primarily a Fortinet security failure. It is the industrialization of three perimeter security anti-patterns that have been documented for years.

Anti-Pattern
Why It Matters in This Campaign
Correct Posture
Internet-exposed management interfaces
Attackers can reach the administrative interface of the firewall directly from the public internet, enabling brute-force and credential-stuffing without passing through any other security control.
Management interfaces accessible only from trusted internal networks or out-of-band management channels. Never exposed to the public internet.
Weak or legacy password hashing (PBKDF1)
FortiOS stored administrator credentials using older hash algorithms susceptible to offline GPU cracking.³ Exported configuration files containing these hashes gave attackers plaintexts without further network access.
PBKDF2 hashing enforced for all administrator accounts. Fortinet issued guidance on migration³; organizations that have not applied it remain exposed regardless of other controls.
No MFA on VPN and administrative access
Compromised credentials alone were sufficient for full access. MFA would have rendered the stolen credential database operationally useless for remote access even if the credentials themselves remained valid.¹²
Phishing-resistant MFA required on all remote access and administrative accounts. CISA's alert names this as a mandatory immediate action.

CISA's June 18 alert names five specific immediate actions for all impacted Fortinet customers with FortiGate appliances and SSL VPN gateways.1 For federal civilian agencies, these actions are mandatory under existing binding operational directives.

CISA Required Action
What It Means in Practice
Terminate sessions and reset credentials
Terminate all active SSL VPN and administrative sessions immediately. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems. Enforce strong password policies.
Ensure secure credential storage
Confirm use of PBKDF2 algorithm for administrator credential storage. Remove weaker legacy hashes per Fortinet's guidance. Applies to FortiOS v7.2.11 and later.
Review logs
Review firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, suspicious accounts, and unauthorized configuration changes covering the exposure window.
Enable phishing-resistant MFA
Require phishing-resistant MFA on all remote access and administrative accounts. Enforce on all external gateways and administrative interfaces. No exceptions.
Reduce attack surface and lock down management
Ensure firewall administration is inaccessible from the public internet. Restrict management interfaces to trusted internal networks. Remove or disable unauthorized accounts.

How BlackBerry Secure Communications Addresses the FortiBleed Threat Class

FortiBleed represents a threat class, not a single incident. Credential-based initial access against perimeter devices is now the dominant technique across nation-state and organized criminal campaigns targeting government and critical infrastructure. Once inside the network perimeter, an attacker controls the infrastructure that communications, identities, and emergency coordination depend on. The relevant question is not only how to prevent perimeter compromise, but what remains protected and operational after it succeeds.

FortiBleed Impact on Your Organization
Why It Matters
BlackBerry Secure Communications Response
Compromised VPN gateway exposes all remote communications to interception
An attacker with firewall administrator credentials controls the encryption termination point for remote access. All traffic passing through the compromised device is visible and modifiable.
BlackBerry® SecuSUITE® routes voice and data communications through a sovereign, independently encrypted channel that does not terminate at or traverse the perimeter device. Interception at the firewall layer does not compromise communications protected by BlackBerry SecuSUITE.
Managed devices connecting through a compromised perimeter become lateral movement vectors
Devices that authenticate through a compromised VPN gateway may be subject to traffic manipulation, credential interception, or policy bypass. Unmanaged or non-compliant devices amplify this risk.
BlackBerry® UEM enforces continuous device posture assessment and access policy controls. Non-compliant devices cannot authenticate to enterprise resources regardless of whether the perimeter device has been compromised. Policy enforcement is independent of the network perimeter.
Primary coordination and alerting infrastructure is degraded or inaccessible during incident response
Security teams responding to a FortiBleed-class compromise may lose access to the same network infrastructure they rely on for coordination, alerting, and communication during the incident.
BlackBerry® AtHoc® operates as an independent, out-of-band crisis communications and mass notification platform. It does not depend on the primary network perimeter for availability. Emergency coordination, personnel alerting, and interagency communication remain operational when the primary environment is compromised.
Identity and access controls dependent on network-layer enforcement are bypassed
Attackers with valid firewall credentials can modify access control lists, disable logging, and create persistent administrative accounts. Network-layer identity enforcement is compromised from the point of initial access.
BlackBerry UEM enforces identity and access policy at the device and application layer, independent of network-layer controls. Certificates, compliance posture, and application-layer authentication policies remain enforced regardless of firewall configuration changes.

The perimeter device is no longer outside the threat model. It is the entry point. Organizations whose communications, identity enforcement, and emergency coordination all depend on the integrity of the network perimeter have no resilience layer when that perimeter is the incident.

BlackBerry Position

FortiBleed did not require a new vulnerability. It required valid credentials, an internet-exposed management interface, and an absence of MFA. The attackers assembled all three at scale across 194 countries. A compromised perimeter device does not just expose the network behind it — it exposes every communication, every coordination channel, and every identity operating through it. BlackBerry UEM enforces device posture and access policy controls that limit what a compromised perimeter device can reach. BlackBerry SecuSUITE removes voice and data communications from the carrier and platform infrastructure that FortiBleed-class attacks are designed to traverse. BlackBerry AtHoc ensures that when perimeter infrastructure is compromised, emergency coordination and crisis communications operate through an independent, authenticated, out-of-band channel that does not depend on the compromised environment.

Citations:

  1. CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure (CISA, June 22, 2026)

  2. Analysis of Reported Credential Compromise of FortiGate Devices (Fortinet PSIRT, June 19, 2026).

  3. FortiBleed: 75,000 Fortinet Firewalls Compromised, Global Enterprises Exposed (Hudson Rock, June 17, 2026).

  4. Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices (Bitdefender, June 22, 2026).

Get updates about the latest in-depth knowledge for secure communications.

The New Standard

Watch the Webinar: The Case for Mission-Critical Communications

Join us for a 45-minute webinar where our experts explore the technical and operational framework to ensure mission-certified secure communications across encryption, architecture, sovereign control, independent validation, and mission orchestration.

Watch now