5 views 15 secs 0 comments

How a massive password-cracking operation spilled credentials for thousands of orgs

In News, Data Breach News
June 19, 2026

Ars Technica reports:

Researchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself.

Nearly 74,000 Fortinet devices from more than 21,000 IP addresses in 194 countries have been compromised and their plaintext credentials exposed online, Bob Diachenko, a security researcher and head of SecurityDiscovery.com, said online and in an interview. He said he found the data after gaining access to the attackers’ command-and-control server and other infrastructure. The exposed data also included the industry, revenue, and employee count for each compromised organization.

Independent researcher Kevin Beaumont reported that “almost all” of the compromised devices remained online as of Wednesday morning.

Read more at Ars Technica.

This is not the first Fortinet breach, as The Data Breach Times’ previous reporting reveals.