
- Home
- Threat Advisories
- NCSC-TAD-2605-001
NCSC-TAD-2605-001
Reference No.: NCSC-TAD-2605-001CVSS 0
FortiBleed leak exposes Fortinet VPN credentials
- Threat Type:
- N/A
- TLP:
- CLEAR
- CVE:
- N/A
Overview
FortiBleed is a cybersecurity incident involving the exposure of VPN credentials from Fortinet FortiGate devices. The leaked data reportedly includes usernames, email addresses, and passwords that could allow unauthorized access. The data is believed to have been collected through a combination of older Fortinet vulnerabilities, brute-force password attacks, stolen configuration files, and credentials obtained from previous security breaches. Security researchers believe the dataset is genuine, although the exact source of the data remains under investigation
Mitigation and Immediate Actions
- 01
Rotate passwords associated with Fortinet VPN and administrative interfaces.
- 02
Enforce MFA.
- 03
Examine gateway logs for suspicious activity.
- 04
Monitor for exposed employee credentials.

