FortiBleed 行動已入侵全球 194 國共 73,932 組 Fortinet 防火牆網址,影響 21,632 個網域,總計超過 11.6 億次登入嘗試——無涉零時差漏洞,純粹利用已外洩或弱密碼。 受害企業包括 Accenture、Comcast、Foxconn、Lenovo、Oracle、Samsung、Siemens、PwC 等世界級公司,以及至少 15 國的政府機構;衝擊最嚴重的產業為 IT 服務、建材與電信業。

Create a landscape editorial hero image for this Studio Global article: What were the key details of the "FortiBleed" campaign that compromised 73,000 Fortinet firewalls worldwide, including the scale of the brea. Article summary: Here is a complete breakdown of the FortiBleed campaign, confirmed by BleepingComputer, TechCrunch, Hudson Rock, Arctic Wolf, and SOCRadar reports from mid-June 2026. All inline citations below come from the published co. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
2026 年 6 月中旬,網路安全研究人員揭露了史上規模最大的網路安全設備憑證盜取行動之一。這起被命名為 「FortiBleed」 的行動,並非透過未知的軟體漏洞(零時差漏洞),而是系統性地竊取、破解並重複使用弱密碼或已外洩的帳密,入侵了橫跨 194 國的數萬台 Fortinet FortiGate 防火牆與 SSL VPN 閘道器 。
這批外洩資料集最初由安全研究員 Volodymyr "Bob" Diachenko 發現,並由 Hudson Rock 進行分析,內容包含 73,932 組獨特的 Fortinet 防火牆網址,對應到 21,632 個受影響的網域 。攻擊者總計對超過 320,000 台 FortiGate 目標發動了約 11.6 億次憑證填充攻擊
。除了帳密,外洩資料還包括有效的管理員與 SSL VPN 憑證、電子郵件地址、明碼密碼、設備設定檔、排程工作(cron jobs)、操作歷史紀錄(bash histories)及資料庫連線字串,等於直接提供了攻擊者活躍的內部基礎設施全景
。
儘管名稱讓人聯想到 Heartbleed 漏洞,FortiBleed 與軟體漏洞完全無關。多家安全公司——包括 TechCrunch、SOCRadar、Hudson Rock 與 Arctic Wolf——均確認 駭客並未使用任何未知漏洞(零時差漏洞) 。
攻擊者採取的是兩階段的供應鏈攻擊模式:
SOCRadar 確認攻擊者已從暴露在網際網路的 FortiGate 設備中,取得了至少 30,791 組驗證過的有效憑證 。Arctic Wolf 的分析則獨立佐證了受害設備數量約在 30,000 到 75,000 台之間
。
多份報告點名的確認受害企業包括 Accenture(埃森哲)、Comcast(康卡斯特)、Foxconn(鴻海)、Lenovo(聯想)、Oracle(甲骨文)、Samsung(三星)、Siemens(西門子)與 PwC(資誠),以及至少 15 個國家的政府機關 。路透社報導指出,遭入侵設備主要集中在美國、印度與台灣
。
受衝擊最嚴重的產業(根據數據分析)為:
與 FortiBleed 同時期,研究人員觀察到有 21 億次暴力破解登入嘗試 針對超過 160,000 台暴露於網際網路的 MSSQL 伺服器,研判背後是同一批威脅行為者 。
SOCRadar 與 Hudson Rock 均將此行動歸因於一個 俄語系的多操作者威脅組織 。攻擊者在受害設備上維持著活躍的後端基礎設施——包括排程工作、遙測回報與即時的憑證盜取循環——顯示這是個精密且持續進行的行動,而非一次性資料盜取
。
Hudson Rock、Arctic Wolf 與 Fortinet 等安全機構建議所有使用 Fortinet 設備的組織立即採取以下行動:
Hudson Rock 已推出一個 免費查詢入口,任何組織均可搜尋其所屬網域,確認是否出現在這份涵蓋 73,932 台設備的憑證外洩資料庫中。此工具已於 2026 年 6 月 17 至 18 日期間對外公開 。
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
FortiBleed 行動已入侵全球 194 國共 73,932 組 Fortinet 防火牆網址,影響 21,632 個網域,總計超過 11.6 億次登入嘗試——無涉零時差漏洞,純粹利用已外洩或弱密碼。
FortiBleed 行動已入侵全球 194 國共 73,932 組 Fortinet 防火牆網址,影響 21,632 個網域,總計超過 11.6 億次登入嘗試——無涉零時差漏洞,純粹利用已外洩或弱密碼。 受害企業包括 Accenture、Comcast、Foxconn、Lenovo、Oracle、Samsung、Siemens、PwC 等世界級公司,以及至少 15 國的政府機構;衝擊最嚴重的產業為 IT 服務、建材與電信業。