← The Craftwork Group  ·  Blog

FortiBleed

FortiBleed: A Firewall Exposure Checklist for PNW Firms

By The Craftwork Group · Published 2026-06-22 · Updated 2026-10-06

FortiBleed is a credential leak that exposed working admin and VPN logins for tens of thousands of Fortinet FortiGate firewalls. We wrote this checklist in June 2026, after CISA's alert. If your dealership or construction office connects staff over a Fortinet or Sophos VPN, the checks still apply. Here is what FortiBleed was, who it hits, and the exact checks to run.

What is FortiBleed, in plain terms?

Security researchers found that attackers pulled configuration files off internet-facing FortiGate devices and cracked the stored password hashes. The result, reported by CISA and several security firms, is valid administrator and SSL VPN credentials for roughly 74,000 firewalls across 194 countries (Recorded Future counted 73,932), which were circulating and being reused when this was written. On June 18, CISA told Fortinet customers to end active VPN and admin sessions, reset every VPN and admin password, and turn on multi-factor authentication. The same crews are brute-forcing Sophos firewalls that have no MFA. Sophos confirmed there is no new flaw on their side. The weak point is an exposed appliance with no second factor.

Does FortiBleed affect my dealership or construction office?

Both of these businesses run on remote access, which is exactly what FortiBleed targets. A dealership has people reaching the DMS, the F and I tools, and accounting from more than one rooftop. A contractor has project managers and field crews connecting from trailers and job-site offices. That convenience runs over a VPN, and a VPN with a leaked admin password is an open door. If you run a dealership in the Pacific Northwest or a construction firm and nobody can tell you, on the spot, whether your firewall is a FortiGate or a Sophos box, that gap is the first thing worth closing.

How do I know if we are exposed?

Run these five checks. None of them needs a consultant to begin:

How would an attacker actually use a leaked password?

The pattern is boring, which is what makes it work. Someone takes a known-good admin or VPN login and signs in like an employee. No alarm fires, because nothing was broken into. In the logs it looks like a normal sign-in, often from an odd hour or an unfamiliar address, which is why a team with no alerting can miss it for weeks. From there they read email, reach file shares, and hunt for the accounting system or the customer database. In a dealership that means deal jackets and credit applications. At a construction firm that means bid files, lien waivers, and the bank details on the next draw. Ransomware crews favor this route because a valid login skips the noisy part of an attack. That is also why a password reset and MFA matter more than any single patch. They turn a working key into a dead one.

What order should we work in?

Order matters. Inventory first, because you cannot protect a device you forgot you own. Rotate credentials second. Turn on MFA everywhere third. Then take the management interface off the public internet. A small IT team can work through this in a day or two when one person owns the list and runs it top to bottom. The shops that get burned are the ones where nobody could say how many firewalls they run or who can log into them. Solid managed IT is mostly that discipline, applied before the bad week instead of during it.

We built a free FortiBleed exposure check for Pacific Northwest dealerships and contractors so you do not have to guess. We walk your firewall inventory, flag the exposed and no-MFA accounts, and hand you a prioritized fix list. Tell us where to look and we will show you exactly where you stand.

Have a support question or need help? Click here