Sensitive Inter-Agency Coordination Data Concentrated in Commercial Collaboration Platforms Produces Single-Breach, Multi-Agency Exposure at Scale
SUBJECT: DHS Inter-Agency Coordination Network Breached STATUS: CISA Advisory AUDIENCE: Government, Defense, Critical Infrastructure Security Leads
Jul 15, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
CISA issued an emergency hardening alert on June 18, 2026, after a credential harvesting campaign dubbed FortiBleed exposed valid administrator and VPN credentials for tens of thousands of internet-facing Fortinet firewalls across government and private sector organizations worldwide.1 No new vulnerability was exploited.2 The attackers used stolen credentials, brute force, and exposed management interfaces.
What FortiBleed Is — and Why It Is Different
On June 13, 2026, security researcher Volodymyr Diachenko discovered an open server containing valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for tens of thousands of organizations.5 Security researcher Kevin Beaumont and Hudson Rock independently confirmed the dataset.5 By June 19, the confirmed device count had reached approximately 86,644 unique devices across 194 countries, representing roughly half of all internet-facing Fortinet firewalls.6
FortiBleed is not a CVE story. There is no patch that closes it. The attackers harvested credentials through a combination of exposed management surfaces, brute-force attacks, credential material recovered from exported Fortinet configuration files, and GPU-based offline password cracking against legacy hash formats. Fortinet's own assessment describes the activity as threat actors reusing credentials from previous incidents and brute-forcing devices with weak password hygiene and no MFA.2
CISA Alert — June 18, 2026
CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways.1
The dataset is structured as a sales catalog. Each entry includes the target organization's industry, revenue, employee count, and country.4 It was not assembled for personal use. It was assembled for sale or coordinated deployment across a criminal team.4-5 An attacker with these credentials can log in remotely, access the firewall and therefore the network behind it, change security settings, and use the device as a persistent foothold.
Exposure Analysis: What the Attackers Had and What They Could Do With It
Companies appearing in the dataset including many confirmed by Hudson Rock, were Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators.⁴ The dataset spans 21,632 unique domains.⁵ The breadth is not incidental — it is the product.
Access Type | What the Attacker Controls | Detection Difficulty |
Firewall administrator credentials | Full device configuration access: routing, filtering rules, logging settings, VPN policies. Can disable security controls, create persistence, and cover tracks. | High — valid credentials produce no authentication alerts |
VPN gateway credentials | Remote access to internal network as an authenticated user. Bypasses perimeter controls entirely. | High — traffic appears as legitimate remote worker session |
Exported configuration files | Complete network topology, internal IP ranges, policy logic, and credential hashes for offline cracking. | N/A — data already exfiltrated before detection |
Legacy PBKDF1 password hashes | Offline GPU cracking yields plaintext passwords, which are then reused across other systems and platforms. | None — cracking occurs entirely off-network |
Lateral movement foothold | Once inside the network via VPN or management interface, attacker pivots to internal systems, domain controllers, and data repositories. | Low — post-exploitation activity mimics normal user behavior |
A credential campaign targeting half the internet-facing Fortinet fleet does not trigger exploit signatures, does not deploy malware at the entry point, and does not announce itself in any way that a perimeter block or intrusion detection system is designed to catch. The detection problem is precisely that the abuse resembles legitimate administrative activity: valid credentials, valid usernames, successful authentication.
Root Cause: Three Design Decisions That Made This Possible at Scale
FortiBleed is not primarily a Fortinet security failure. It is the industrialization of three perimeter security anti-patterns that have been documented for years.
Anti-Pattern | Why It Matters in This Campaign | Correct Posture |
Internet-exposed management interfaces | Attackers can reach the administrative interface of the firewall directly from the public internet, enabling brute-force and credential-stuffing without passing through any other security control. | Management interfaces accessible only from trusted internal networks or out-of-band management channels. Never exposed to the public internet. |
Weak or legacy password hashing (PBKDF1) | FortiOS stored administrator credentials using older hash algorithms susceptible to offline GPU cracking.³ Exported configuration files containing these hashes gave attackers plaintexts without further network access. | PBKDF2 hashing enforced for all administrator accounts. Fortinet issued guidance on migration³; organizations that have not applied it remain exposed regardless of other controls. |
No MFA on VPN and administrative access | Compromised credentials alone were sufficient for full access. MFA would have rendered the stolen credential database operationally useless for remote access even if the credentials themselves remained valid.¹² | Phishing-resistant MFA required on all remote access and administrative accounts. CISA's alert names this as a mandatory immediate action. |
Recommended Actions: What CISA Is Directing Organizations to Do
CISA's June 18 alert names five specific immediate actions for all impacted Fortinet customers with FortiGate appliances and SSL VPN gateways.1 For federal civilian agencies, these actions are mandatory under existing binding operational directives.
CISA Required Action | What It Means in Practice |
Terminate sessions and reset credentials | Terminate all active SSL VPN and administrative sessions immediately. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems. Enforce strong password policies. |
Ensure secure credential storage | Confirm use of PBKDF2 algorithm for administrator credential storage. Remove weaker legacy hashes per Fortinet's guidance. Applies to FortiOS v7.2.11 and later. |
Review logs | Review firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, suspicious accounts, and unauthorized configuration changes covering the exposure window. |
Enable phishing-resistant MFA | Require phishing-resistant MFA on all remote access and administrative accounts. Enforce on all external gateways and administrative interfaces. No exceptions. |
Reduce attack surface and lock down management | Ensure firewall administration is inaccessible from the public internet. Restrict management interfaces to trusted internal networks. Remove or disable unauthorized accounts. |
How BlackBerry Secure Communications Addresses the FortiBleed Threat Class
FortiBleed represents a threat class, not a single incident. Credential-based initial access against perimeter devices is now the dominant technique across nation-state and organized criminal campaigns targeting government and critical infrastructure. Once inside the network perimeter, an attacker controls the infrastructure that communications, identities, and emergency coordination depend on. The relevant question is not only how to prevent perimeter compromise, but what remains protected and operational after it succeeds.
FortiBleed Impact on Your Organization | Why It Matters | BlackBerry Secure Communications Response |
Compromised VPN gateway exposes all remote communications to interception | An attacker with firewall administrator credentials controls the encryption termination point for remote access. All traffic passing through the compromised device is visible and modifiable. | BlackBerry® SecuSUITE® routes voice and data communications through a sovereign, independently encrypted channel that does not terminate at or traverse the perimeter device. Interception at the firewall layer does not compromise communications protected by BlackBerry SecuSUITE. |
Managed devices connecting through a compromised perimeter become lateral movement vectors | Devices that authenticate through a compromised VPN gateway may be subject to traffic manipulation, credential interception, or policy bypass. Unmanaged or non-compliant devices amplify this risk. | BlackBerry® UEM enforces continuous device posture assessment and access policy controls. Non-compliant devices cannot authenticate to enterprise resources regardless of whether the perimeter device has been compromised. Policy enforcement is independent of the network perimeter. |
Primary coordination and alerting infrastructure is degraded or inaccessible during incident response | Security teams responding to a FortiBleed-class compromise may lose access to the same network infrastructure they rely on for coordination, alerting, and communication during the incident. | BlackBerry® AtHoc® operates as an independent, out-of-band crisis communications and mass notification platform. It does not depend on the primary network perimeter for availability. Emergency coordination, personnel alerting, and interagency communication remain operational when the primary environment is compromised. |
Identity and access controls dependent on network-layer enforcement are bypassed | Attackers with valid firewall credentials can modify access control lists, disable logging, and create persistent administrative accounts. Network-layer identity enforcement is compromised from the point of initial access. | BlackBerry UEM enforces identity and access policy at the device and application layer, independent of network-layer controls. Certificates, compliance posture, and application-layer authentication policies remain enforced regardless of firewall configuration changes. |
The perimeter device is no longer outside the threat model. It is the entry point. Organizations whose communications, identity enforcement, and emergency coordination all depend on the integrity of the network perimeter have no resilience layer when that perimeter is the incident.
BlackBerry Position
FortiBleed did not require a new vulnerability. It required valid credentials, an internet-exposed management interface, and an absence of MFA. The attackers assembled all three at scale across 194 countries. A compromised perimeter device does not just expose the network behind it — it exposes every communication, every coordination channel, and every identity operating through it. BlackBerry UEM enforces device posture and access policy controls that limit what a compromised perimeter device can reach. BlackBerry SecuSUITE removes voice and data communications from the carrier and platform infrastructure that FortiBleed-class attacks are designed to traverse. BlackBerry AtHoc ensures that when perimeter infrastructure is compromised, emergency coordination and crisis communications operate through an independent, authenticated, out-of-band channel that does not depend on the compromised environment.
Citations:
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure (CISA, June 22, 2026)
Analysis of Reported Credential Compromise of FortiGate Devices (Fortinet PSIRT, June 19, 2026).
FortiBleed: 75,000 Fortinet Firewalls Compromised, Global Enterprises Exposed (Hudson Rock, June 17, 2026).
Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices (Bitdefender, June 22, 2026).
Sensitive Inter-Agency Coordination Data Concentrated in Commercial Collaboration Platforms Produces Single-Breach, Multi-Agency Exposure at Scale
SUBJECT: DHS Inter-Agency Coordination Network Breached STATUS: CISA Advisory AUDIENCE: Government, Defense, Critical Infrastructure Security Leads
Jul 15, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
CISA issued an emergency hardening alert on June 18, 2026, after a credential harvesting campaign dubbed FortiBleed exposed valid administrator and VPN credentials for tens of thousands of internet-facing Fortinet firewalls across government and private sector organizations worldwide.1 No new vulnerability was exploited.2 The attackers used stolen credentials, brute force, and exposed management interfaces.
What FortiBleed Is — and Why It Is Different
On June 13, 2026, security researcher Volodymyr Diachenko discovered an open server containing valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for tens of thousands of organizations.5 Security researcher Kevin Beaumont and Hudson Rock independently confirmed the dataset.5 By June 19, the confirmed device count had reached approximately 86,644 unique devices across 194 countries, representing roughly half of all internet-facing Fortinet firewalls.6
FortiBleed is not a CVE story. There is no patch that closes it. The attackers harvested credentials through a combination of exposed management surfaces, brute-force attacks, credential material recovered from exported Fortinet configuration files, and GPU-based offline password cracking against legacy hash formats. Fortinet's own assessment describes the activity as threat actors reusing credentials from previous incidents and brute-forcing devices with weak password hygiene and no MFA.2
CISA Alert — June 18, 2026
CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways.1
The dataset is structured as a sales catalog. Each entry includes the target organization's industry, revenue, employee count, and country.4 It was not assembled for personal use. It was assembled for sale or coordinated deployment across a criminal team.4-5 An attacker with these credentials can log in remotely, access the firewall and therefore the network behind it, change security settings, and use the device as a persistent foothold.
Exposure Analysis: What the Attackers Had and What They Could Do With It
Companies appearing in the dataset including many confirmed by Hudson Rock, were Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators.⁴ The dataset spans 21,632 unique domains.⁵ The breadth is not incidental — it is the product.
Access Type | What the Attacker Controls | Detection Difficulty |
Firewall administrator credentials | Full device configuration access: routing, filtering rules, logging settings, VPN policies. Can disable security controls, create persistence, and cover tracks. | High — valid credentials produce no authentication alerts |
VPN gateway credentials | Remote access to internal network as an authenticated user. Bypasses perimeter controls entirely. | High — traffic appears as legitimate remote worker session |
Exported configuration files | Complete network topology, internal IP ranges, policy logic, and credential hashes for offline cracking. | N/A — data already exfiltrated before detection |
Legacy PBKDF1 password hashes | Offline GPU cracking yields plaintext passwords, which are then reused across other systems and platforms. | None — cracking occurs entirely off-network |
Lateral movement foothold | Once inside the network via VPN or management interface, attacker pivots to internal systems, domain controllers, and data repositories. | Low — post-exploitation activity mimics normal user behavior |
A credential campaign targeting half the internet-facing Fortinet fleet does not trigger exploit signatures, does not deploy malware at the entry point, and does not announce itself in any way that a perimeter block or intrusion detection system is designed to catch. The detection problem is precisely that the abuse resembles legitimate administrative activity: valid credentials, valid usernames, successful authentication.
Root Cause: Three Design Decisions That Made This Possible at Scale
FortiBleed is not primarily a Fortinet security failure. It is the industrialization of three perimeter security anti-patterns that have been documented for years.
Anti-Pattern | Why It Matters in This Campaign | Correct Posture |
Internet-exposed management interfaces | Attackers can reach the administrative interface of the firewall directly from the public internet, enabling brute-force and credential-stuffing without passing through any other security control. | Management interfaces accessible only from trusted internal networks or out-of-band management channels. Never exposed to the public internet. |
Weak or legacy password hashing (PBKDF1) | FortiOS stored administrator credentials using older hash algorithms susceptible to offline GPU cracking.³ Exported configuration files containing these hashes gave attackers plaintexts without further network access. | PBKDF2 hashing enforced for all administrator accounts. Fortinet issued guidance on migration³; organizations that have not applied it remain exposed regardless of other controls. |
No MFA on VPN and administrative access | Compromised credentials alone were sufficient for full access. MFA would have rendered the stolen credential database operationally useless for remote access even if the credentials themselves remained valid.¹² | Phishing-resistant MFA required on all remote access and administrative accounts. CISA's alert names this as a mandatory immediate action. |
Recommended Actions: What CISA Is Directing Organizations to Do
CISA's June 18 alert names five specific immediate actions for all impacted Fortinet customers with FortiGate appliances and SSL VPN gateways.1 For federal civilian agencies, these actions are mandatory under existing binding operational directives.
CISA Required Action | What It Means in Practice |
Terminate sessions and reset credentials | Terminate all active SSL VPN and administrative sessions immediately. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems. Enforce strong password policies. |
Ensure secure credential storage | Confirm use of PBKDF2 algorithm for administrator credential storage. Remove weaker legacy hashes per Fortinet's guidance. Applies to FortiOS v7.2.11 and later. |
Review logs | Review firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, suspicious accounts, and unauthorized configuration changes covering the exposure window. |
Enable phishing-resistant MFA | Require phishing-resistant MFA on all remote access and administrative accounts. Enforce on all external gateways and administrative interfaces. No exceptions. |
Reduce attack surface and lock down management | Ensure firewall administration is inaccessible from the public internet. Restrict management interfaces to trusted internal networks. Remove or disable unauthorized accounts. |
How BlackBerry Secure Communications Addresses the FortiBleed Threat Class
FortiBleed represents a threat class, not a single incident. Credential-based initial access against perimeter devices is now the dominant technique across nation-state and organized criminal campaigns targeting government and critical infrastructure. Once inside the network perimeter, an attacker controls the infrastructure that communications, identities, and emergency coordination depend on. The relevant question is not only how to prevent perimeter compromise, but what remains protected and operational after it succeeds.
FortiBleed Impact on Your Organization | Why It Matters | BlackBerry Secure Communications Response |
Compromised VPN gateway exposes all remote communications to interception | An attacker with firewall administrator credentials controls the encryption termination point for remote access. All traffic passing through the compromised device is visible and modifiable. | BlackBerry® SecuSUITE® routes voice and data communications through a sovereign, independently encrypted channel that does not terminate at or traverse the perimeter device. Interception at the firewall layer does not compromise communications protected by BlackBerry SecuSUITE. |
Managed devices connecting through a compromised perimeter become lateral movement vectors | Devices that authenticate through a compromised VPN gateway may be subject to traffic manipulation, credential interception, or policy bypass. Unmanaged or non-compliant devices amplify this risk. | BlackBerry® UEM enforces continuous device posture assessment and access policy controls. Non-compliant devices cannot authenticate to enterprise resources regardless of whether the perimeter device has been compromised. Policy enforcement is independent of the network perimeter. |
Primary coordination and alerting infrastructure is degraded or inaccessible during incident response | Security teams responding to a FortiBleed-class compromise may lose access to the same network infrastructure they rely on for coordination, alerting, and communication during the incident. | BlackBerry® AtHoc® operates as an independent, out-of-band crisis communications and mass notification platform. It does not depend on the primary network perimeter for availability. Emergency coordination, personnel alerting, and interagency communication remain operational when the primary environment is compromised. |
Identity and access controls dependent on network-layer enforcement are bypassed | Attackers with valid firewall credentials can modify access control lists, disable logging, and create persistent administrative accounts. Network-layer identity enforcement is compromised from the point of initial access. | BlackBerry UEM enforces identity and access policy at the device and application layer, independent of network-layer controls. Certificates, compliance posture, and application-layer authentication policies remain enforced regardless of firewall configuration changes. |
The perimeter device is no longer outside the threat model. It is the entry point. Organizations whose communications, identity enforcement, and emergency coordination all depend on the integrity of the network perimeter have no resilience layer when that perimeter is the incident.
BlackBerry Position
FortiBleed did not require a new vulnerability. It required valid credentials, an internet-exposed management interface, and an absence of MFA. The attackers assembled all three at scale across 194 countries. A compromised perimeter device does not just expose the network behind it — it exposes every communication, every coordination channel, and every identity operating through it. BlackBerry UEM enforces device posture and access policy controls that limit what a compromised perimeter device can reach. BlackBerry SecuSUITE removes voice and data communications from the carrier and platform infrastructure that FortiBleed-class attacks are designed to traverse. BlackBerry AtHoc ensures that when perimeter infrastructure is compromised, emergency coordination and crisis communications operate through an independent, authenticated, out-of-band channel that does not depend on the compromised environment.
Citations:
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure (CISA, June 22, 2026)
Analysis of Reported Credential Compromise of FortiGate Devices (Fortinet PSIRT, June 19, 2026).
FortiBleed: 75,000 Fortinet Firewalls Compromised, Global Enterprises Exposed (Hudson Rock, June 17, 2026).
Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices (Bitdefender, June 22, 2026).
%3Aquality(100)&w=3840&q=75)