FortiBleed Exploited: Tracking Initial Access Broker Dark_Alpha on Darkforums

July 15, 2026

In mid-June 2026, security researchers identified a large-scale credential compromise campaign targeting Fortinet FortiGate firewalls, quickly dubbed FortiBleed. Unlike a traditional zero-day, FortiBleed is not tied to a single new vulnerability. Instead, threat actors systematically extracted configuration files from internet-facing FortiGate devices and cracked the stored password hashes — exploiting the fact that many organizations running older FortiOS versions continued to store administrator credentials as legacy SHA-256 hashes rather than the more secure PBKDF2 format Fortinet introduced in FortiOS 7.2.11, 7.4.8, and 7.6.1. Devices upgraded from earlier versions retain SHA-256 hashes until each administrator logs in post-upgrade, leaving a window of exposure that the campaign actively exploited at scale.

The result: verified working administrator credentials for between 73,932 and 86,000 devices across 21,632 organizations in 194 countries — roughly half of all internet-facing FortiGate firewalls at the time of discovery. The United States, India, and Mexico were among the most heavily affected countries. CISA issued an advisory on June 18, 2026 urging organizations to rotate credentials, enforce MFA, and restrict management interface access.

Darkforums is currently the fastest-growing English-language cybercrime forum on the darknet. Originally launched as “DARK4RMY Forums” by a hacking group called DarkArmy, it rebranded following the April 2025 collapse of BreachForums and rapidly absorbed much of that platform’s displaced user base — recording a 600% surge in activity between April and June 2025. Now operated by administrators AnonOne and Knox, the forum hosts over 12,700 registered members and offers a tiered membership model (VIP, MVP, and GOD ranks) alongside a full range of cybercrime content: leaked databases, stealer logs, combo lists, malware tools, and access listings. It is on this forum that DarkOwl researchers identified the threat actor Dark_Alpha advertising FortiGate access tied to the FortiBleed campaign.

On June 20th, 2026, a threat actor using the handle “Dark_Alpha” — an MVP-tier member of Darkforums — posted a thread titled “[ FortiBleed ] FortiGate / Fortinet Access 35k ip”.

This content was identified and captured by DarkOwl Vision during routine dark web collection.

DarkOwl analysts identified a corroborating listing on the Russian-language Exploit forum, posted by an actor operating under a distinct handle but sharing an identical TOX ID — suggesting a high likelihood of the same underlying threat actor. The following screenshot was captured via DarkOwl Vision.

“Dark_Alpha” is an MVP member of Darkforums. On Darkforums, MVP membership is available to any user for a one-time fee of €40, granting elevated privileges such as the ability to change usernames (twice), +60 forum credits, a higher daily post limit of 10, and the ability to edit or delete posts for up to two months — as detailed in Screenshot.

Dark_Alpha is advertising FortiGate/Fortinet access to 35,000 corporate targets for $25,000. According to the actor, the dataset spans 194 countries — a geographic footprint that aligns precisely with the confirmed scope of the FortiBleed campaign as documented by Arctic Wolf and CISA, lending the listing a degree of credibility. The data is structured in the format “url:user:pass:domain:revenue.” The actor provided a TOX ID for contact.

According to the actor’s profile, Dark_Alpha joined Darkforums on February 28, 2025, and has since created 6 threads and 11 posts, accumulating a forum reputation score of 6. The profile signature reads “ALPHA-GROUP”.

The actor also lists a QTOX ID on their profile and can be reached via the forum’s private messaging feature.

Beyond the FortiBleed listing, Dark_Alpha has been actively posting access listings targeting organizations across Bolivia, Vietnam, India, the United States, and Brazil — including at least two alleged government entities. DarkOwl researchers identified the following threads attributed to this actor on Darkforums:

  • On June 9th, 2026, Dark_Alpha listed administrator-level GitLab access to a Bolivian government entity — identified by the thread title as AGETIC (Bolivia’s national e-government agency) — with reported revenue of $69.6 million, priced at $1,000
  • On June 11th, 2026, the actor listed admin-level GitLab access to a Brazilian government entity for $2,000. The target’s revenue is claimed at $50 million. The actor claims the access was obtained via a zero-day exploit — a claim DarkOwl cannot independently verify and which predates the public FortiBleed disclosure, suggesting this may be a separate intrusion vector. The listing includes tokens, APIs, database keys, source code, and environment variables.
  • On June 12th, 2026, Dark_Alpha listed FortiGate VPN access to a Vietnamese entity with over 90 hosts, super-admin rights, and claimed revenue of $22 million, priced at $1,000 . As with the Brazil listing, the actor claims access was obtained via a zero-day exploit. Given that this listing also predates the public FortiBleed disclosure, whether it is related to FortiBleed or an independent intrusion is unclear.
  • Later that same day, the actor posted a second listing: FortiGate VPN/portal access to an Indian entity in the Medical Devices & Equipment sector, with claimed revenue of $3 billion and 1,193 hosts.
  • On June 21st, 2026 — three days after CISA’s FortiBleed advisory — Dark_Alpha listed 6,355 valid FortiGate device accesses from U.S.-based entities, explicitly citing the FortiBleed vulnerability as the acquisition method. Given that India, the U.S., and Mexico collectively account for a significant share of the 73,000+ compromised devices identified by researchers, a U.S.-focused subset of that scale is plausible. Targeted organizations span a revenue range of $1 million to $200 billion. The bulk price is $7,000, with individual access also available. Notably, the actor accepted payment via the forum’s escrow system — a mechanism that may indicate a higher degree of transactional credibility.

Note on escrow: An escrow system acts as a trusted intermediary, holding payment until the buyer confirms receipt of the promised goods — a mechanism designed to reduce fraud between anonymous parties and one that more established actors tend to offer.

While Dark_Alpha has been active on Darkforums since February 2025, some earlier threads are no longer accessible due to the forum’s repeated TLD changes. DarkOwl maintains historical records across all known Darkforums domains, enabling researchers to track actor activity across those domain transitions.

DarkOwl analysts identified a corroborating finding wherein a network access broker operating on the Russian-language forum XSS, who shared a Telegram contact, utilized the identical handle “Dark_Alpha.” While this handle overlap suggests a potential link to the actor discussed above, attribution across forums cannot be confirmed with certainty, and the possibility of handling reuse by a distinct threat actor cannot be ruled out at this time.

The activity attributed to Dark_Alpha illustrates how rapidly IABs capitalize on newly disclosed — and in this case, still unfolding — credential exposure events. In under two weeks following the public emergence of FortiBleed, this actor posted listings spanning six countries, two alleged government entities, and thousands of compromised devices across critical sectors including government IT and medical devices. The listing of 6,355 U.S. FortiGate accesses posted the same week as the CISA advisory underscores how quickly the darknet economy responds to public disclosures: rather than dampening activity, news coverage appears to have been used as a sales tool.

The “ALPHA-GROUP” signature warrants further monitoring. Whether this represents a larger team or a solo actor cultivating a brand, the pace and breadth of Dark_Alpha’s listings in such a compressed timeframe — and the actor’s apparent access to data that aligns with the confirmed FortiBleed scope — suggests an established and operationally capable presence in the access brokering ecosystem.

It is also worth noting that separate research linked the original FortiBleed data exposure to a threat actor operating under the handle “SantaAd” on a Russian-language cybercrime forum. Whether Dark_Alpha is independently operating, reselling data obtained from SantaAd, or represents a separate arm of the same operation is an open question and a thread worth pulling.

Organizations running FortiGate or Fortinet devices should treat FortiBleed as an active, exploited threat and verify patch status immediately. Rotating credentials, enforcing MFA, and removing management interfaces from the public internet remain the highest-priority mitigations per CISA’s guidance. DarkOwl’s Vision UI enables security teams to monitor darknet forums for mentions of their organization, IP ranges, and credentials in near real-time — providing early warning of exposure before it can be operationalized by threat actors like Dark_Alpha.


Keep up with us. Follow us on LinkedIn.

See why DarkOwl is the Leader in Darknet Data

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.