FortiBleed: 74,000 Admin Credentials Cracked From Devices That Were Already Patched
74,000 Fortinet admin credentials cracked by GPU clusters from config backups stolen via old vulnerabilities. Patching the device wasn't enough.

On June 18, 2026, researchers revealed that attackers had built a database of over 74,000 working Fortinet FortiGate administrative credentials, cracked using GPU clusters from configuration backup files stolen through previously exploited vulnerabilities.
The critical detail: the devices from which the configuration files were stolen had already been patched. The organizations applied the vendor fix for the original vulnerability. They rotated API keys. They followed the advisory guidance. What they did not do was change their administrative passwords after patching. The configuration backup files, stolen before the patch was applied, contained hashed admin credentials. Those hashes were cracked offline at scale using GPU-accelerated password cracking.
This is the fourth distinct Fortinet security event in 2026 alone. AI-assisted exploitation of FortiGate in February. FortiClient EMS endpoint manager takeover in early June. FortiSandbox security appliance exploitation in mid-June. And now FortiBleed's credential campaign on June 18. Four independent research teams and criminal actors found four different ways to compromise four different Fortinet products. The pattern is unmistakable: any vendor whose products hold administrative network access at scale has become a systematic research target.
Why Patching Wasn't Enough
The FortiBleed campaign exploits a gap in most organizations' incident response process. When a vulnerability advisory is published and a patch is applied, the assumption is that the incident is resolved. The device is no longer vulnerable. The risk is mitigated.
But if the attacker exfiltrated data before the patch was applied, the patch does not un-steal that data. Configuration backup files contain hashed administrative passwords. With modern GPU clusters, cracking those hashes is a matter of time and compute budget. A well-funded attacker with access to cloud GPU instances can crack most password hashes in hours or days, depending on the hashing algorithm and password complexity.
The 74,000 cracked credentials demonstrate that patching without credential rotation is an incomplete response. When building the CIAM platform that served over a billion users, we implemented automatic credential rotation as part of every security incident response, not as an optional follow-up. The principle is simple: if an attacker had access to your system before the patch, assume they took everything they could read. Hashed passwords are readable. Therefore, hashed passwords must be rotated. The strength of your defense here depends heavily on which password hashing algorithm protected those credentials in the first place.
What Organizations Should Do
Rotate all FortiGate administrative credentials immediately. If your FortiGate appliances were ever affected by any Fortinet vulnerability in 2025 or 2026, change every administrative password. Do not assume that patching the vulnerability protected credentials that were accessible before the patch.
Enforce phishing-resistant MFA on all edge device administration. FIDO2 security keys or certificate-based authentication for firewall and VPN administration eliminates the risk of cracked passwords being used for access.
Audit your edge device fleet systematically. The four Fortinet events in 2026 demonstrate that addressing each vulnerability in isolation is insufficient. Organizations with deep Fortinet deployments need a holistic security review across all Fortinet products, not reactive patching of individual CVEs. A zero trust security model that assumes any device can be compromised limits the blast radius when credentials leak.
Treat configuration backups as crown jewels. Configuration files contain credentials, certificates, and network architecture details. They should be encrypted, access-controlled, and treated with the same sensitivity as database backups.
Key Takeaways
- 74,000 Fortinet admin credentials were cracked offline using GPU clusters from configuration backups stolen via earlier vulnerabilities
- The affected devices had been patched, but administrative passwords were not rotated after patching
- This is the fourth distinct Fortinet security event in 2026, with four different products exploited by four different groups
- Patching without credential rotation is an incomplete incident response
- Configuration backup files contain hashed credentials that can be cracked offline at scale
- Edge device vendors whose products hold network administrative access have become systematic attack targets
Deepak Gupta is the co-founder and CEO of GrackerAI. He previously founded a CIAM platform that scaled to serve over 1B+ users globally. He writes about AI, cybersecurity, and digital identity at guptadeepak.com.
Get the newsletter
New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.