What happened
A financially motivated Russian-speaking initial access broker has been linked to FortiBleed, a credential-harvesting campaign active since February 2026 that has compromised more than 430,000 FortiGate firewalls and collected upward of 110 million credentials worldwide. The operation combines automated scanning for exposed services, brute-force attacks, and custom-built tooling to systematically strip access credentials at scale. Separately, two core members of the notorious cybercrime collective Scattered Spider entered guilty pleas in a United Kingdom court on the opening day of what had been scheduled as a six-week trial, resolving charges tied to an August 2024 attack that severely disrupted Transport for London's public transit network.
Why it matters for your business
FortiGate appliances are perimeter devices that sit at the edge of corporate networks, meaning compromised credentials can hand attackers a direct path past existing defenses and into internal systems. Organizations running unpatched or internet-exposed FortiGate devices should treat this as an active threat requiring immediate audit of exposed management interfaces and a forced password reset for all associated accounts. The Scattered Spider guilty pleas underscore that social engineering and SIM-swapping tactics — the group's signatures — remain a viable threat to enterprises of all sizes, not just critical infrastructure operators. Both cases reinforce the practical imperative of layering multi-factor authentication, network segmentation, and privileged-access controls rather than relying on perimeter hardware alone.
What to watch next
Investigators will likely pursue the broader FortiBleed broker network to identify downstream buyers of the harvested credential lists, making further intrusion disclosures probable in the weeks ahead. The Scattered Spider sentencing proceedings in the UK will set a precedent for how Western courts treat financially motivated cybercrime crews with transnational reach. Security teams should monitor Fortinet's advisory channel for any new indicators of compromise or emergency patches linked to the FortiBleed campaign.
