Massive breach spills credentials for thousands of sensitive networks

Massive breach spills credentials for thousands of sensitive networks

A significant security breach affecting Fortinet firewalls has been revealed, allowing Russian-speaking hackers to gain extensive access to numerous prominent organizations, including Oracle, Chevron, and Lenovo. Security researcher Bob Diachenko, who heads SecurityDiscovery.com, reported that nearly 74,000 Fortinet devices across more than 21,000 IP addresses in 194 countries have been compromised, with their plaintext credentials now available online. Diachenko discovered the breach by accessing the attackers’ command-and-control server, revealing sensitive data about compromised organizations, including their industry, revenue, and employee counts. Independent researcher Kevin Beaumont confirmed that as of Wednesday morning, “almost all” of the affected devices were still operational. He verified with multiple organizations listed in the attackers’ logs that the exposed credentials are legitimate and up-to-date. Following the breach, many threat actors exploited compromised devices to infiltrate affected organizations' centralized authentication systems, such as Radius servers and Microsoft Active Directory. This incident represents approximately half of all Internet-facing Fortinet firewalls, according to data from Shodan. Researchers from Hudson Rock noted that the breach impacts nearly every sector of the global economy, highlighting the extensive reach of the attackers’ database containing verified credentials for some of the largest companies worldwide. In light of this alarming breach, Diachenko, Beaumont, and Hudson Rock have urged Fortinet users to assess their networks for potential compromises immediately. Hudson Rock has also provided a search engine to help locate affected domains. The scale of this operation is unprecedented, as the attackers began by conducting mass scans for FortiGate remote login endpoints and used a custom-built binary with 25,000 threads to bombard these endpoints with various login credentials, resulting in successful breaches that provided them with unprecedented access to the organizations’ internal networks.

Sources : Ars Technica

Published On : Jun 17, 2026, 19:55

AI
The Shift in Human Cognition: Embracing AI as a Collaborative Tool

As technology continues to evolve, a notable shift is occurring in the relationship between humans and artificial intell...

Business Insider | Jul 25, 2026, 09:50
The Shift in Human Cognition: Embracing AI as a Collaborative Tool
Science
Vision Breakthrough: US Startup Launches Groundbreaking Retina Chip in Europe

Science Corp is poised to introduce a revolutionary retina chip in Europe, designed to restore partial vision for indivi...

Business Today | Jul 25, 2026, 01:00
Vision Breakthrough: US Startup Launches Groundbreaking Retina Chip in Europe
Startups
Warner Bros. Takes Legal Action Against Amazon Over Executive Poaching Allegations

Warner Bros. Discovery has initiated legal proceedings against Amazon, accusing the tech giant of unlawful interference ...

TechCrunch | Jul 25, 2026, 21:25
Warner Bros. Takes Legal Action Against Amazon Over Executive Poaching Allegations
AI
Shifting Focus: The Cost-Effectiveness of AI Models Takes Center Stage

In recent years, the AI sector has been intensely focused on identifying the most advanced models. While this pursuit re...

Business Insider | Jul 25, 2026, 13:10
Shifting Focus: The Cost-Effectiveness of AI Models Takes Center Stage
Cybersecurity
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants

In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...

TechCrunch | Jul 25, 2026, 21:00
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants
View All News