FortiBleed is not just another story about exposed Fortinet credentials. It is a far more concrete sign: access to FortiGate firewalls is becoming a commodity on the criminal market.
In incidents of this kind, the initial focus is almost always on the numbers: how many devices, how many domains, how many countries, how many credentials. But the real issue is not just the scale of the leak. The issue is what happens next.
When VPN and administrative access credentials for perimeter devices start appearing on underground forums, the nature of the risk changes. We are no longer dealing with a simple exposed dataset. We are dealing with a monetisation chain.
Why FortiGate is such an attractive target
A FortiGate access credential is not comparable to just any email password.
A firewall or SSL VPN gateway is often located at the most critical point in the infrastructure: between the internet and the internal network. In many organisations, it manages remote access, network policies, VPN authentication, segmentation, routing and administrative access.
For an attacker, a valid FortiGate credential can mean:
- entry into the corporate perimeter without needing to use malware;
- seemingly legitimate VPN access;
- the ability to move towards internal services;
- access to Active Directory systems;
- opportunities for persistence or the creation of new accounts;
- reselling access to ransomware groups or Initial Access Brokers.
This explains why FortiGate credentials are so highly valued on the criminal markets. They are not just selling a single credential. They are selling a potential gateway into the network.
Underground listings: from individual credentials to national-scale stockpiles
Monitoring of underground sources shows a clear increase in listings related to FortiGate and Fortinet.
Between April and June 2026, listings appeared relating to various countries and business sectors, including France, the United States, Greece, Finland, Vietnam, Argentina, India, Mexico and the United Arab Emirates.
Some examples observed:
- “FRANCE FORTIGATE 1115 ACCESS”;
- “USA FORTIGATE 6355 ACCESS”;
- “[FortiBleed] FortiGate / Fortinet Access 35k IP”;
- “FortiGate / Fortinet Access 35k IP”;
- “Greece – FortiGate”;
- “Finland – FortiGate”;
- “FORTIGATE VPN ACCESS (Vietnam)”;
- “Fortigate VPN [Argentina 62M$]”;
- “Fortigate Access {1.6B$ India Corp}”;
- “FORTIGATE ACCESS CORP [$873.8 Million] Mexico”;
- “FORTIGATE VPN ACCESS [UAE $283.3 million]”;
- “FORTIGATE VPN ACCESS [$426 Million Corp revenue] India”.
The most interesting detail is the scale. We’re not just talking about individual, high-value corporate access points. In some cases, the listings refer to thousands or tens of thousands of IP addresses.
This marks a shift in the business model. FortiGate access is no longer sold solely as a specific target. It is packaged, segmented and offered as inventory.
FortiBleed as a market accelerator
It is not possible to automatically attribute every underground listing to FortiBleed. That would be a misguided oversimplification.
However, the context is clear: criminal interest in FortiGate was already high before the case received widespread media coverage, and it intensified further following the publication of public analyses.
This makes FortiBleed an accelerator.
On the one hand, there is a large-scale dataset of Fortinet/FortiGate credentials. On the other, there is a market already poised to absorb, resell and reuse VPN and administrative access credentials. The result is an ecosystem in which the compromise of a firewall can be monetised multiple times: by the initial actor who collects the credentials, by the broker who validates them, by the seller who segments them, and by the group that uses them for the final intrusion.
The chain is simple:
credential collection → cracking → validation → classification → sale → initial access → lateral movement.
In this scheme, FortiGate becomes the industrialised point of entry.
The role of distributed cracking
One of the most technically significant elements concerns the potential infrastructure used to manage credential cracking.
In the FortiBleed context, tools and workflows compatible with distributed password cracking activities have been cited, including Hashcat and Hashtopolis. The latter is particularly interesting because it allows multiple agents to be orchestrated and cracking workloads to be distributed across multiple nodes.
In a legitimate context, Hashtopolis can be used for security audits and to verify password strength. In a criminal context, the same type of infrastructure can be used to convert hashes collected from configurations or authentication processes into plaintext credentials.
The difference lies not in the tool, but in the operational context.
Hashtopolis triage: 437 candidates and three confidence levels
During the analysis, 437 Hashtopolis candidates identified from Internet exposure sources and infrastructure correlations were taken into consideration.
The dataset was divided into several priority levels:
- 1 ‘critical’ item;
- 36 ‘high’ items;
- 61 ‘medium’ items;
- 339 ‘low’ items.
This distribution should not be interpreted as a list of FortiBleed servers. It is a map of exposure and correlation. The distinction is important.
An exposed Hashtopolis host is not automatically a criminal node. It may be a legitimate laboratory, a test environment, a training infrastructure, a password audit system or a deployment left online by mistake.
The value of triage lies in distinguishing between a strong IOC and a mere technical correlation.
85.11.187.8: a high-priority IOC in the FortiBleed context
Among the findings, the IP address 85.11.187.8 is the most significant.
The IP address appears in the CTI/OSINT context linked to FortiBleed and has been treated as a high-priority indicator. Not as self-sufficient evidence of the entire operation, but as a node to be monitored with particular attention.
Its significance stems from a combination of several factors: its presence within the FortiBleed context, an anomalous exposed surface area, indicators consistent with infrastructure used for credential harvesting or operational activities, and a web service that is not fully functional and returns a database connection error.
A particularly sensitive detail concerns the presence of a graphical session accessible without authentication. In an ordinary context, this would already be a serious problem. In a context associated with credential collection and distributed cracking, it becomes a matter of significant investigative interest.
The point is not to automatically attribute the entire environment to a single actor. The point is that 85.11.187.8 represents a high-priority indicator within the FortiBleed perimeter and warrants continuous monitoring.
Hashtopolis 0.14.8: the strongest correlation
In addition to the main IOC, the triage highlighted a group of hosts with a stronger technical correlation than the rest of the dataset.
In particular, some panels exhibit the same Hashtopolis profile:
- version 0.14.8;
- commit 617878e;
- consistent classic static assets;
- visible behaviour consistent with the same application profile.
The most relevant hosts in this group are:
- 176.109.182.36:8080;
- hashtopolis.68cavalry.army:443;
- 203.129.17.36:8080;
- 209.209.8.89:8080.
This is a strong technical correlation. However, it does not confirm that they belong to the same FortiBleed infrastructure.
The correct wording is: highly correlated Hashtopolis cluster, useful for watchlists and CTI enrichment.
In other words: these hosts are of interest because they share a specific technical profile. But they should not be described as “confirmed FortiBleed servers” without further evidence.
Infrastructure clusters: indicators to monitor, not conclusions
The dataset also reveals larger groups that resemble operational fleets. Some ranges display recurring patterns: recurring ports, identical Hashtopolis versions, the same provider and neighbouring IP addresses.
Among the most interesting clusters are:
- 51.161.137.0/24;
- 51.161.143.0/24;
- 195.209.214.0/24.
These groups are useful for monitoring, but must be treated with caution. A concentration of Hashtopolis panels within the same range does not automatically prove a criminal link.
It may indicate a legitimate cracking environment, a research laboratory, a service provider, a training project or infrastructure unrelated to FortiBleed.
Their main value lies in investigation: passive DNS, ASNs, certificate history, exposure timelines and correlation with any new IOCs.
Why the risk does not end with the lookup
One of the most common mistakes in responding to incidents such as FortiBleed is to limit oneself to checking whether one’s domain appears in a public tool.
The problem is that not appearing in a lookup does not mean there is no risk.
There are several scenarios in which an organisation may be exposed even without appearing in a known dataset:
- FortiGate credentials reused from previous incidents;
- VPN accounts never rotated following previous compromises;
- administrative passwords saved in exported configurations;
- weak credentials or those derived from corporate patterns;
- generic accounts still active;
- management interfaces or SSL VPNs exposed to the internet;
- insufficient logs to reconstruct past access attempts.
Furthermore, when an attacker uses valid credentials, the activity may appear to be a normal login. There isn’t always an exploit. There isn’t always malware. There isn’t always an immediate alert.
For this reason, remediation cannot depend solely on confirmation in the FortiBleed dataset.
What organisations must do
Organisations using FortiGate should take immediate action, regardless of whether they appear in the public or private datasets associated with FortiBleed.
The two minimum actions are:
- enable MFA for all FortiGate access, including VPN and administration;
- carry out a complete rotation of FortiGate passwords, including VPN accounts, administrative accounts and associated privileged credentials.
These measures must be regarded as preventative, not optional.
Password rotation should be accompanied by a review of active accounts, recent logins, administrative users, configuration changes and the exposure of management interfaces.
If suspicious logins, new unauthorised accounts or anomalous configuration changes are detected, the device must be treated as potentially compromised.
The real lesson from FortiBleed
FortiBleed highlights a significant shift in the criminal market.
Access to perimeter devices is no longer merely a technical by-product of a compromise. It has become a structured product, marketable by country, sector, turnover and volume.
Underground listings relating to FortiGate demonstrate that the market is already active. The triage of Hashtopolis infrastructure shows that the distributed cracking component is a key element to monitor. The IOC 85.11.187.8 highlights how a single piece of infrastructure can become significant not only for what it contains, but for the operational context in which it appears.
The message for defenders is clear: do not wait for your domain to appear on a public list.
If an organisation uses FortiGate, it must treat this moment as a crucial opportunity to strengthen its perimeter: MFA, credential rotation, account reviews and reduced exposure.
The moment a FortiGate access credential is sold in bulk on an underground forum, it is no longer just a credential.
It is a gateway to the network that comes with a price tag.
Analysis by Vasily Kononov – Threat Intelligence Lead, CYBEROO
