FortiBleed and the anatomy of an unforced error: how 86,000 stolen passwords, not a software flaw, opened Foreign Office networks, NHS suppliers, and global shipping to the same campaign- 280
July 7, 2026
By the time the UK's National Cyber Security Centre issued an urgent alert on July 5, the campaign it was responding to had already been running for five months. FortiBleed, as researchers came to call it, compromised more than 80,000 Fortinet firewall and VPN devices across 194 countries, yielding a verified database of over 86,000 working administrator credentials. What makes the incident notable is not its scale alone but its cause: Fortinet has confirmed there is no new software vulnerability at the root of it. This was a brute-force credential campaign against organizations that recycled passwords, skipped multi-factor authentication, or failed to retire login details that should have been discarded during routine upgrades — and it reached from British government ministries to the operational core of global maritime trade.
The mechanism itself is almost mundane, which is precisely what makes it durable. Cydome's threat-intelligence unit found that 87 percent of exposed Fortinet devices still had internet-facing management interfaces active, and that 63 percent of harvested credentials belonged to default or built-in administrator accounts that had never been renamed. Attackers were not exploiting a zero-day; they were recovering old, valid credentials that organizations had updated software around but never fully replaced, then testing them against live devices — a pattern that succeeds precisely because it targets institutional habit rather than code. That distinction matters for remediation: patching alone does not close this exposure, and Cydome's own guidance, echoing the U.S. Cybersecurity and Infrastructure Security Agency, calls for terminating active sessions, resetting passwords wholesale, and enabling MFA rather than waiting on a vendor fix.
In the UK, the exposure reached directly into government. Stolen credentials belonging to Foreign Office staff and local council employees in Derbyshire and Waltham Forest, along with IT personnel at British embassies in Thailand and Mauritius, surfaced for sale on dark web forums under the handle "SantaAd," priced at roughly £44,000. Researcher Volodymyr Diachenko, who first identified the breach, said the stolen data provided access to core Foreign Office networks and warned other departments could be similarly affected. The exposure extended into the National Health Service and its supply chain — pharmacies and medicine suppliers among them — a detail that carries particular weight given recent history. A June 2024 ransomware attack on pathology supplier Synnovis, which followed a comparable initial-access pattern, cancelled more than a thousand operations and two thousand appointments and has since been linked to over 120 cases of patient harm and at least one death. A separate, unrelated intrusion at Higham Lane School in Nuneaton, which disabled fire alarms and electronic gates alongside IT systems, rounds out a pattern that UK cyber insurance brokers have flagged as testing what public-sector cover can realistically absorb — a concern sharpened by a government proposal to ban ransomware payments across the NHS, councils, and schools, removing a recovery option precisely where security budgets are most constrained.

The same campaign's reach into global maritime and energy infrastructure suggests this was never a UK-specific operation but an indiscriminate harvesting exercise that happened to catch high-value targets wherever they were exposed. Cydome identified 703 satellite-linked IP addresses tied to maritime satcom providers among the leaked data, and reported more than 250 affected maritime firms, the majority of them shipowners and ship management companies rather than back-office administrative functions — 41.5 percent shipping and freight companies, 31.2 percent offshore contractors, 10.7 percent newbuild and repair yards, and 6.7 percent port authorities and logistics operators. Cydome's founder characterized this distribution as consistent with the campaign hitting the operational core of maritime trade rather than peripheral IT, a distinction with real consequence in a sector where compromised administrator access can extend from data theft into control over operational technology aboard vessels and at port facilities. Attribution remains where campaigns like this typically settle: suggestive but unconfirmed.

The underlying code is reportedly written in Russian, and the NCSC has previously described a pattern of Russian intelligence services tolerating, rather than directly operating, proxy hacker groups that conduct exactly this kind of credential-harvesting campaign at scale. No evidence of direct state involvement has been established, and that ambiguity is not merely an intelligence footnote — it has immediate financial consequence. Under Lloyd's LMA5567 policy wording, state-linked attacks are excluded from cyber cover only where they cause major detrimental impact on a state's essential services, a threshold most commercially targeted incidents will not meet regardless of who is ultimately behind them. That leaves insurers and policyholders to resolve attribution uncertainty in policy language before an incident occurs rather than after, at a moment when ransomware and malware already account for 51 percent of UK cyber insurance claims, up sharply from 32 percent the year before. FortiBleed did not need a state sponsor to become a state-relevant problem: a five-month credential-recycling campaign, run against ordinary institutional negligence, proved sufficient to reach a foreign ministry, a national health system, and the satellite links of global shipping simultaneously.