FortiBleed Check
Check whether your organization's FortiGate firewall or Fortinet VPN credentials appear in the active FortiBleed breach dataset. Enter a domain or IP for an instant free exposure check.
Results in seconds — see exactly what attackers saw50,000+ organizations checked their exposure

The team behind FortiBleed
First to document and name it
We identified the campaign, coined "FortiBleed", and published the first public analysis.
Attributed to Lynx and INC Ransom
Our attribution work linked the campaign's infrastructure and tooling to the Lynx and INC Ransom groups.
Global coordinated response
We coordinated with national CERTs worldwide and made thousands of responsible disclosures to affected organizations.
Research featured by


Our FortiBleed research
FortiBleed: discovery and attack chain analysis
The first public documentation of the campaign — how it worked, who was targeted, and why we named it FortiBleed.
Read the reportReport 02Attribution: Lynx and INC Ransom
The evidence trail connecting FortiBleed operations to the Lynx and INC Ransom groups, from infrastructure to tooling overlaps.
Read the reportWe Need Your Help. If you represent a National CERT, Government Agency, MSSP, MSP, Incident Response Team, Threat Intelligence Provider, Law Enforcement Agency, or another trusted cybersecurity organization, contact us at [email protected]. We are sharing relevant FortiBleed datasets free of charge to accelerate victim notification efforts and help reduce the impact of this operation.
F.A.Q.
Find answers to common questions about the FortiBleed VPN leak and FortiBleed