CREDENTIAL-STUFFING
- [2026.06.24]FortiBleed from the Target Side: The Corpus [Part 1/3]
We ran an internet-facing FortiGate honeypot for a month. It logged about 447,600 login attempts from about 34,600 IP addresses, and for three days we captured every submitted credential in cleartext. The corpus is not brute force: it is a stolen corpus of real corporate credentials being recycled, complete with FortiGate service accounts that exist only inside a device configuration backup. This is Part 1 of three: what FortiBleed actually is, and what the spray looks like from inside the device it targets.