FortiBleed and the maritime sector: a real exposure?
A recap of the facts first. FortiBleed was disclosed in mid-June 2026 by independent researcher Volodymyr “Bob” Diachenko, who specialises in hunting down databases and servers left open on the Internet. The leak did not surface at a victim’s site. He found it on the attackers’ side: a poorly secured server exposing their tooling, their logs and the credential set itself. The operation, which he attributes to a Russian-speaking multi-operator group, is said to have harvested and then cracked the authentication hashes of tens of thousands of FortiGate appliances, enriching each entry with the target’s industry, revenue and headcount - enough to plan future attacks. Several researchers validated part of the batch, among them the British Kevin Beaumont, who confirmed the authenticity of a sample of administration credentials.
