Widespread hacking campaign 'FortiBleed' compromises tens of thousands of Fortinet devices
Story essentials
Russian-speaking cybercriminal group
Global (India, US, Taiwan, Mexico most affected)
June 2026
This page is produced by collecting and structuring multiple public reports. Sections based only on reporting or testimony affect the displayed assessment, and the page is updated when new information is identified.
About this article
COMPAMIR Editorial Team
The COMPAMIR editorial team brings together public reporting and links to the original coverage. We update the page as new information emerges.
Read our editorial policy- Earlier version 16/17/2026, 7:30:31 PM
Cybercriminals have compromised over 30,000 to 73,000 Fortinet firewalls and VPNs globally. The attack, dubbed 'FortiBleed', exploits weak or reused credentials rather than unknown software vulnerabilities. Affected organizations include major global companies like Accenture, Lenovo, and Samsung.
Read next
Prioritized by shared people, places, and events.
Anthropic reports widespread misuse of Claude models by cybercriminals and state actors
Anthropic identified misuse of Claude models for cyberattacks, surveillance, and weapons development. Actors include Russian espionage groups and data-theft gangs like ShinyHunters. Misuse cases include automating cyber kill chains and developing guidance software for weapons. The report covers activity disrupted between December 2025 and August 2026.
Related book
Cybersecurity and Cyberwar: What Everyone Needs to Know
Author: P.W. Singer and Allan Friedman
This book provides a comprehensive overview of the cyber threat landscape, explaining how vulnerabilities in infrastructure and credential management are exploited by state and non-state actors to compromise global enterprises.
As an Amazon Associate, COMPAMIR earns from qualifying purchases.