By NHI Mgmt Group Editorial TeamDomain: Breaches & IncidentsSource: AppgatePublished July 16, 2026

TL;DR: FortiBleed exposed a structural flaw in internet-facing remote access: roughly half of Fortinet firewalls had credentials harvested, with attackers reusing leaked passwords, cracking weak hashes, and pivoting into internal networks, according to Appgate. Patch cycles did not matter because the gateway itself was the target, not a software flaw.


At a glance

What this is: FortiBleed is a credential-harvesting campaign against internet-facing Fortinet gateways that showed why perimeter remote access remains a persistent identity risk rather than a patchable vulnerability.

Why it matters: It matters because IAM, PAM, and NHI teams still have to govern exposed authentication points, credential reuse, and post-login network reach when remote access is treated as a perimeter problem.

👉 Read Appgate's analysis of FortiBleed and perimeter credential harvesting


Context

FortiBleed is a credential exposure problem, not a software vulnerability problem. The issue sits in the perimeter access model itself: an internet-facing gateway must be reachable to function, which makes it discoverable, scannable, and attractive to credential-spraying attackers.

For identity teams, that means the control surface is not just authentication at the gateway. It is the combination of exposed access, weak credential storage, reused credentials, and excessive post-login reach into internal systems. The article shows why patching alone cannot compensate for an access architecture that trusts a valid login too much.

The article’s starting position is typical for internet-facing remote access: once a gateway is reachable, attackers can test it at scale. That is the normal condition of perimeter exposure, not an edge case.


Key questions

Q: How should teams respond when internet-facing gateway credentials are harvested?

A: Containment starts with terminating active sessions, resetting administrative and remote-access credentials, and removing public exposure where possible. Teams should also validate whether the gateway granted broad network reach after login, because stolen credentials are only half the problem. The real risk is that one successful authentication opens too much of the environment.

Q: Why do exposed VPN gateways remain such a high-risk identity control?

A: Because they are designed to be reachable, they become easy to scan and easy to test at scale. Once a valid credential works, the gateway often trusts the session too much and provides broad internal access. That makes remote access an identity and privilege problem, not only an edge security problem.

Q: What do security teams get wrong about router patching?

A: Teams often assume patching is the whole answer, but router risk also depends on exposure, lifecycle status, and service configuration. If a device is internet-facing, end-of-life, or still running remote access features, the remaining attack window stays open even after a fix is published. Exposure reduction has to accompany patching.

Q: Who is accountable when stolen credentials are used for stealthy internal movement?

A: Accountability should sit with the owners of identity, endpoint, and directory controls because the failure crosses all three domains. If stolen credentials can be replayed and lateral movement is not detected, that is a governance gap, not just a security event. Frameworks such as NIST CSF and PAM governance should define clear ownership for containment and review.


Technical breakdown

Why internet-facing gateways become identity targets

An internet-facing VPN or firewall gateway is discoverable by design. That makes it easy to scan, spray, and brute-force at scale, especially when attackers can reuse credentials from earlier breaches. Once a valid login succeeds, the gateway often becomes a high-trust entry point into the internal network. The technical problem is not only authentication failure. It is the architectural assumption that a reachable login point can safely mediate broad network access after a single successful check.

Practical implication: Treat the exposed gateway as an identity attack surface, not just an edge control, and reduce what a single credential can unlock.

Why credential reuse and weak hash storage compound the risk

FortiBleed shows the compounding effect of exposed credentials, weak password storage, and legacy configuration exports. Attackers do not need a new vulnerability when they can reuse valid credentials, crack exported hashes, and authenticate as a trusted user. That turns old identity debt into present-day compromise. This is the classic NHI and access-control failure mode: credentials outlive the security assumptions that surrounded them when they were issued or exported.

Practical implication: Inventory exposed secrets and exported configuration material as active attack paths, not archival artifacts.

Why VPN access often becomes a lateral movement bridge

A VPN that authenticates once and then opens network reach creates a large blast radius. FortiBleed shows how cracked gateway access can pivot into internal environments, including Active Directory, because the access model grants more reach than the task requires. That is not a routing issue alone. It is a privilege-scoping problem in which identity verification at the edge is used as a proxy for trust across the rest of the network.

Practical implication: Scope remote access to specific resources rather than network segments and limit what authenticated users can traverse.


Threat narrative

Attacker objective: The objective was to convert a stolen or cracked gateway credential into trusted internal access that could be reused for lateral movement and follow-on compromise.

  1. Entry occurred through harvested or brute-forced credentials against internet-facing Fortinet gateways and SSL VPN services. Escalation followed when attackers reused valid logins, cracked legacy password hashes, and obtained trusted access to connected internal environments. Impact came through lateral movement into internal Active Directory and related enterprise systems, turning a gateway credential into broad network exposure.
  • MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
  • Palo Alto Networks Key Breach — Supply chain breach compromises Palo Alto Networks and exposes customer credentials and information.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Perimeter access is an identity model failure, not a vulnerability class. FortiBleed reinforces that internet-facing gateways create a standing trust problem: if the device is reachable, it can be tested, and if a credential works, the network often opens too far. That turns authentication into a broad access grant rather than a constrained identity decision. Practitioners should treat exposed remote access as an identity governance issue, not a patching workflow.

Gateway credentials behave like non-human identities once they are reusable and long-lived. The moment a firewall, VPN, or appliance credential is stored, exported, or reused, it becomes an NHI control problem: rotation, exposure, scope, and revocation all matter. The article shows that a leaked credential can become a durable access path across countries and sectors. The implication is that standing credential governance must extend to infrastructure access points, not just applications and service accounts.

Half of internet-facing devices having harvested credentials is a visibility and accountability failure, not just an incident count. That scale shows how quickly exposed access points can accumulate identity risk when MFA, credential hygiene, and reach restrictions are weak. The lesson for NHI governance is that discovery without enforcement produces an inventory of exploitable trust. Teams should assume exposed gateways will be targeted as a class, not as isolated events.

Identity blast radius is the real metric that FortiBleed exposes. Once a single external login can reach internal Active Directory, the security boundary is already too permissive. This is where perimeter access models fail governance tests: they certify the login, then trust the session too much. Practitioners should measure how far one valid credential can move inside the environment, because that is what attackers monetise.

Single Packet Authorization and direct-routed access change the attack preconditions, not just the controls. The article’s architecture discussion shows why hiding the target matters before identity checks even begin. That is a governance signal for teams evaluating remote access: if a control only hardens the exposed gateway, it still preserves the target. The better question is whether the access model removes the target class altogether.

From our research:

  • Roughly half of all internet-facing Fortinet firewalls had their credentials harvested, according to LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
  • When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
  • For a broader breach lens, see 52 NHI Breaches Analysis for recurring credential exposure patterns and root causes.

What this signals

Perimeter access remains a governance debt. FortiBleed shows that when remote access is externally reachable, the identity problem is not just whether authentication succeeds but how much access a single credential can unlock. Teams should review whether their access model still assumes that a verified login is enough to trust the session.

Identity blast radius should become a core metric. If one external credential can reach internal directory services or other high-value systems, the organisation has not reduced risk, it has relocated it. That is why modern access programmes need to measure post-login reach, not just MFA adoption or patch status.

The practical signal for practitioners is simple. If a remote access control still depends on a visible public target, then credential theft, brute force, and reuse remain in play. For teams building stronger identity posture, the next step is to align remote access with resource-scoped control patterns and lifecycle discipline, not broader trust.


For practitioners

  • Reduce exposed remote access surfaces Map every internet-facing gateway, VPN, and firewall login that accepts credentials from the public internet. Classify which of those endpoints create broad network reach after authentication and prioritise them for redesign or removal.
  • Reset trust around legacy credentials Treat exported configuration files, weak password storage, and reused credentials as active compromise paths. Force credential rotation, invalidate old hashes where possible, and verify that no administrative credential can be reused across related devices.
  • Limit post-login reach Replace broad network access with resource-scoped access so that a single validated login cannot traverse internal segments freely. If a credential is stolen, the attack should stop at the first resource boundary instead of opening the environment.
  • Enforce MFA on every externally reachable access point Require MFA for all internet-facing administrative and remote access workflows, including appliances and gateways. MFA will not fix exposure by itself, but it does raise the cost of credential reuse and brute-force attacks.
  • Test the blast radius of one stolen login Run tabletop and technical validation exercises that start with one valid external credential and measure how far it can move. The exercise should reveal whether the access model is still a perimeter trust model in disguise.

Key takeaways

  • FortiBleed shows that internet-facing remote access can fail as an identity model even when no software vulnerability is present.
  • The scale of credential harvesting proves that exposed gateways create a repeatable attack surface, not a one-off incident.
  • The control that matters most is reducing what a stolen credential can reach, because patching alone cannot fix architectural trust.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Credential harvesting and weak rotation are central to this gateway exposure case.
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral MovementThe article centers on credential access followed by internal pivoting.
NIST CSF 2.0PR.AC-4Remote access should enforce least privilege and constrained access paths.
NIST SP 800-53 Rev 5AC-6The breach pattern shows excessive privilege after authentication.
NIST Zero Trust (SP 800-207)The article argues for removing exposed trust points at the edge.

Map exposed gateway activity to Credential Access and Lateral Movement, then prioritise containment on those paths.


Key terms

  • Perimeter access model: A perimeter access model is a design that exposes a login point on the public internet and then trusts the authenticated session to carry users into the internal network. In identity terms, it concentrates risk at one reachable control and often grants more reach than the task requires.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Credential Reuse: Credential reuse happens when the same password, token, or secret can unlock multiple systems or sessions. It increases breach impact because one stolen credential can become a wide-ranging access path. The control problem is not only theft, but the amount of trust packed into each reusable secret.
  • Single Packet Authorization: Single Packet Authorization is an access pattern where a protected service stays hidden from ordinary connection attempts until it receives a valid cryptographic request. It changes remote access from an always-visible gate to a concealed entry point that only reveals itself after authorization succeeds.

What's in the full article

Appgate's full article covers the operational detail this post intentionally leaves for the source:

  • The June 2026 advisory sequence and how Fortinet, CISA, and the UK NCSC responded across the incident window.
  • The direct-routed Zero Trust and Single Packet Authorization architecture details that Appgate argues remove the exposed target.
  • The specific U.S. Air Force and General Dynamics context behind the deployment example and scale claims.
  • The step-by-step containment actions Appgate recommends for teams running exposed Fortinet or similar gateway products.

👉 Appgate's full article covers the attack chain, gateway exposure logic, and the Zero Trust response model.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org