110 Million Passwords Stolen: The Silent Cyber Operation Hidden Inside Enterprise Firewalls

Discover the story behind FortiBleed, the massive credential-harvesting campaign targeting over 430,000 FortiGate firewalls and stealing 110 million credentials worldwide.

Illustration showing hackers harvesting credentials through compromised FortiGate firewalls in a global cyber espionage operation

It started with a firewall.

Not a ransomware alert. Not a flashing warning from a Security Operations Center. Not even a suspicious login attempt.

Just a firewall quietly doing its job.

Somewhere in India, a mid-sized technology company began another normal workday. Employees logged into VPNs. Administrators authenticated through Active Directory. Remote workers connected to internal systems. Business continued as usual.

What nobody realized was that someone else was watching.

Every login.

Every authentication request.

Every password hash moving through the network.

And they weren't alone.

Across the globe, hundreds of thousands of organizations were unknowingly becoming part of one of the largest credential-harvesting operations ever discovered.

Researchers would later call it FortiBleed.

By then, more than 110 million credentials had already been collected.

The Discovery That Opened Pandora's Box

The story began when cybersecurity researcher Volodymyr "Bob" Diachenko stumbled upon what appeared to be a routine exposed server.

At first glance, it looked like another internet misconfiguration.

But as investigators followed the breadcrumbs, they uncovered something far larger.

One server led to ten.

Ten led to fifty.

Fifty became more than one hundred and fifty interconnected systems spread across multiple hosting providers.

What emerged was not a lone hacker's setup.

It was an industrial-scale cybercrime operation.

Researchers found evidence of infrastructure monitoring over 430,000 FortiGate firewalls worldwide, with tens of thousands of devices under active surveillance.

The deeper they looked, the more alarming the picture became.

This wasn't chaos.

It was a business.

Why FortiGate Firewalls Became The Perfect Target

Most organizations view firewalls as defenders.

Digital gatekeepers standing between attackers and critical systems.

The FortiBleed operators saw them differently.

They saw opportunity.

FortiGate appliances sit at the edge of enterprise networks. They handle VPN traffic, authentication requests, remote access sessions, and administrator logins.

In other words, they see everything.

Instead of breaking into networks through flashy zero-day exploits, the attackers chose a quieter path.

They turned security devices into listening posts.

The result was devastatingly effective.

Phase One: Hunting The Targets

The attackers began by scanning the internet.

Not hundreds of systems.

Not thousands.

Millions.

Using high-speed reconnaissance tools, they searched for exposed FortiGate devices around the world.

But this wasn't random.

Researchers discovered that targets were ranked based on company size, estimated revenue, and business value.

The operation wasn't interested in everyone.

It wanted organizations most likely to pay, provide valuable access, or open doors to larger networks.

Every target was carefully selected.

Every scan served a purpose.

Phase Two: Knocking On The Front Door

Once a target was identified, the attackers didn't immediately exploit vulnerabilities.

Instead, they went after something simpler.

Passwords.

Using customized credential dictionaries specifically built for FortiGate environments, they launched credential stuffing and brute-force attacks against VPN portals and administrative interfaces.

Their logic was simple.

Why spend months finding software vulnerabilities when employees often reuse passwords?

In many cases, the front door was already unlocked.

Phase Three: Turning Firewalls Into Spies

This was where FortiBleed became truly dangerous.

Researchers uncovered a custom tool called FortigateSniffer.

Unlike traditional malware, it didn't install suspicious software or deploy ransomware.

Instead, it leveraged legitimate FortiOS functionality.

The attackers essentially instructed compromised firewalls to quietly observe traffic moving through them.

And the data they collected was gold.

Kerberos authentications.

NTLM credentials.

LDAP requests.

RADIUS logins.

Remote Desktop sessions.

Database authentications.

The very identity systems organizations depend on every day.

To avoid suspicion, the operation reportedly ran primarily during business hours.

While employees worked, the attackers listened.

Blending into normal network activity.

Invisible.

Patient.

Effective.

Phase Four: Breaking The Passwords

Captured credentials were only the beginning.

The next challenge was cracking them.

Researchers discovered an advanced password-cracking infrastructure powered by distributed GPU clusters and cloud computing resources.

Automated systems continuously attempted to recover passwords from stolen authentication data.

When successful, the results were immediately delivered to operators through real-time management systems.

This wasn't a hacker sitting in a basement guessing passwords.

It was an assembly line.

Credential theft at industrial scale.

Phase Five: Exploiting The Access

The moment a password was recovered, the clock started ticking.

Researchers documented cases where attackers moved from credential recovery to network exploitation within minutes.

They navigated Active Directory environments.

Escalated privileges.

Accessed sensitive systems.

Extracted valuable data.

In one reported incident, a defense contractor experienced data theft shortly after attackers recovered authentication credentials.

There was no dramatic malware deployment.

No loud ransomware note.

Just rapid, calculated access to valuable information.

The Business Behind The Breach

One of the most fascinating discoveries wasn't technical.

It was organizational.

The FortiBleed infrastructure resembled a professional operation more than a traditional hacking group.

Separate systems handled reconnaissance.

Dedicated servers validated credentials.

Specialized infrastructure managed cracking operations.

Proxy networks rotated traffic.

Operators collaborated across shared environments.

Researchers believe the group functions as an Initial Access Broker (IAB), a growing category of cybercriminals specializing in obtaining access to corporate networks and selling that access to others.

Think of them as cyber real estate agents.

They don't always launch the final attack.

They simply sell the keys.

And business is booming.

Why Small Businesses Should Be Worried

Perhaps the most surprising finding was who the attackers targeted.

Contrary to popular belief, the primary victims weren't massive multinational corporations.

Nearly two-thirds of affected organizations employed fewer than 200 people.

Most generated under $100 million in annual revenue.

Why?

Because smaller organizations often lack dedicated security teams, advanced monitoring capabilities, and mature incident response programs.

Attackers understand this.

They know that compromising a smaller company is often easier than breaching a Fortune 500 enterprise.

And sometimes, those smaller organizations provide access to much larger customers.

The Bigger Lesson

FortiBleed represents a fundamental shift in cybercrime.

For years, organizations focused on patching vulnerabilities.

And they should.

But attackers increasingly understand something important.

They don't always need software flaws.

Sometimes they only need identities.

A valid username and password can bypass security controls that stop malware, block exploits, and trigger alarms.

That's what makes FortiBleed so significant.

It wasn't primarily an attack on technology.

It was an attack on trust.

On the digital identities that power modern business.

What Organizations Should Do Now

If your organization uses FortiGate devices or relies heavily on remote access infrastructure, now is the time to act.

Immediate priorities include:

  • Rotate VPN and administrative credentials.

  • Enforce Multi-Factor Authentication (MFA).

  • Restrict public access to management interfaces.

  • Review authentication logs for unusual activity.

  • Monitor Kerberos, VPN, and privileged account usage.

  • Conduct credential hygiene assessments.

  • Investigate signs of unauthorized lateral movement.

The organizations that respond quickly may stop an intrusion before it becomes a breach.

The ones that don't may discover too late that the attackers have already been watching.

Don't Wait for the Breach to Tell the Story

FortiBleed is a reminder that modern cyberattacks don't always begin with malware or vulnerabilities. Sometimes, they start with a single stolen credential and unfold silently across an entire organization.

The question is no longer if attackers will target identities and access systems, it's whether your organization can detect, respond, and recover before significant damage is done.

At White Knight, we help organizations strengthen their cyber resilience through proactive security assessments, threat detection, incident response, digital forensics, and managed security services. Whether you're securing critical infrastructure, enterprise networks, or cloud environments, preparedness remains your strongest defense.

While FortiBleed demonstrates the devastating impact of delayed detection, our blog "The Intern Who Saved the Company: A Real Lesson in Incident Response" tells the opposite story, how one observant intern helped uncover suspicious activity and triggered an incident response process that protected the organization from a potentially catastrophic breach.

Read the story and discover why incident response isn't just about technology, it's about people, processes, and acting before it's too late.