Campaign

Roiese: FortiBleed-Sourced Resale of Access to Taiwanese Enterprises

An initial access broker operating as Roiese is selling network access to 96 Taiwanese enterprises on the dark web and Telegram. Cross-referencing Hudson Rock's public dataset indicates the data most likely originates from the June 2026 FortiBleed credential leak. The list is the attacker's own claim, and the sample alone cannot prove that any organization was breached. Organizations whose supply chain touches the affected domains should immediately rotate the relevant credentials to cut off password-spray abuse.

Dinlon · Published

Regions Taiwan Industries Cross-sector Platforms FortiGate Attribution high
actor Roiese campaign FortiBleed credential leak technique Initial access brokering

Key findings

  • This is an initial access broker (IAB) secondary-distribution event in which a seller using the alias Roiese is offering network access to 96 Taiwanese enterprises on the DarkForums dark web forum and Telegram, sourced from the June 2026 FortiBleed credential leak.
  • The sample the attacker provided contains only "domain + revenue + employee band" and no FortiGate URLs, credentials, IPs, or passwords; the sample alone cannot prove any organization was breached and should be treated as attacker-claimed exposure, not a confirmed event.
  • Cross-referencing the 96 domains against Hudson Rock's public FortiBleed dataset, 89 hit (92.7%, compared 2026-07-24), supporting the assessment that the list originates from FortiBleed.
  • The list spans listed manufacturers, telecom, media, retail, shipping and logistics, and biotech and medical, and includes several security / IT managed-service providers; if the latter are exposed at the perimeter, the risk spills over to their clients through managed relationships — a supply-chain risk.
  • The Roiese account was newly registered in June 2026 and is filled with FortiBleed-related sale posts; we assess it to be an access broker monetizing the leak rather than a long-established threat entity.
  • We recommend that organizations whose supply chain touches the affected domains immediately rotate the relevant credentials, confirm FortiOS has moved to PBKDF2 and removed old hashes, and enable phishing-resistant MFA to cut off password-spray abuse.

On 17 July 2026, a seller on Telegram calling themselves “I’m Rois” posted a message explicitly tagging “Taiwan” as the target and offered a file, Taiwan Sample Access.txt, for prospective buyers to preview. After FTV News reporter Su En-min covered the event on 23 July 2026 under the headline “Exclusive: Hackers Target Taiwan! 90 Companies Named, Nearly 20 Listed Firms Caught in a Security Storm,” it spread rapidly across Taiwan’s security community. This report investigates the event, which we designate the “Roiese” leak.

Important caveat: The list of enterprises described here consists of targets unilaterally claimed by the attacker. The sample the attacker provided contains no FortiGate URLs, credentials, IPs, or passwords, and the sample alone cannot prove that any enterprise was breached or currently faces risk. To avoid causing secondary harm to unverified parties, this report does not publish individual enterprises or domains; for any concern, defer to each organization’s official statement.

FortiBleed background

This event stems from the large-scale FortiBleed credential leak of mid-June 2026. Security researcher Volodymyr “Bob” Diachenko found an exposed server during scanning that held a large volume of valid Fortinet VPN credentials — usernames, emails, and plaintext passwords — totaling 73,932 firewall URLs and 21,632 domains across 194 countries. Hudson Rock and researcher Kevin Beaumont sampled and verified the data as genuine, and the case was named “FortiBleed.”

Unlike Heartbleed, this is not a zero-day. Fortinet attributes it mainly to reuse of credentials leaked in prior incidents (FG-IR-26-060, FG-IR-25-647) and brute-forcing of devices with weak passwords and no MFA. The key weakness is credential storage: only from FortiOS 7.2.11/7.4.8/7.6.1 did it switch to PBKDF2, so on devices upgraded from older versions where the administrator never re-logged in, passwords remained as salted SHA-256, easy to crack offline. Beaumont, however, notes that the IPs in this dataset largely do not overlap with the 2025 Belsen Group leak, judges it not to be repackaged old data, and remains skeptical of Fortinet’s “purely reused existing credentials” framing.

Taiwan had 3,637 devices in the dataset, third globally after India and the United States, with IT services the most affected sector. CISA issued an alert on 18 June, urging organizations to terminate all SSL VPN and admin sessions and reset passwords, confirm PBKDF2 adoption and remove old hashes, review firewall, VPN, and domain-controller logs, enable phishing-resistant MFA, and reduce management-interface exposure.

Attacker distribution

In this event, the seller operated under the name “Roiese” on the dark web forum DarkForums and a public Telegram channel, and on 17 July 2026 posted leak intelligence about Taiwan, offering Taiwan Sample Access.txt for prospective buyers to preview. No indicators of a completed sale have been observed.

The attacker's Telegram channel posting a Taiwan flag and the Taiwan Sample Access.txt sample file; the contact handle is redacted

A closer look at DarkForums shows the account was newly registered in late June 2026, with posts concentrated on multiple FortiBleed-related access listings from the same period. We assess it to be an access-broker account created to monetize this leak, not a long-established threat entity. A check of Chinese-language underground markets found no related listings.

Roiese's DarkForums profile, showing a June 2026 join date and recent-only posting activity

File analysis

Per the attacker’s sample, there are 282 total rows, 96 unique domains after deduplication, and 186 duplicates; each row follows the fixed format domain revenue <revenue> <employee-band> Employees Taiwan.

By sector, the list spans listed manufacturers (electronics contract manufacturing/assembly, panels and optoelectronics, semiconductors, precision machinery and motion control, materials and chemicals), telecom, media and live-streaming, retail and shopping malls, shipping and logistics, and biotech and medical devices, down to SMEs and religious/arts organizations; employee sizes range from 5000+ to 1-10. Notably, the list also includes several security / IT managed-service providers; if such vendors are exposed at the perimeter, the risk spills over to their clients through managed relationships — the supply-chain dimension that most warrants attention in this event.

Sourcing and cross-verification

The list itself contains no Fortinet artifacts, so whether it originates from FortiBleed cannot be self-evidenced from the sample and must be cross-checked against an authoritative external dataset. We used Hudson Rock’s Fortinet leak dataset as the baseline; on comparison (2026-07-24), 89 of the 96 domains hit (92.7%), each accompanied by a redacted FortiGate login address and FortiGuardID. Taking the security-service provider with the most rows in the list (33) as an example, it maps to roughly 38 redacted login addresses in the Hudson Rock dataset:

http://220.130.***.***:4433/login    ************@***.***   TW
https://114.32.***.***/login         ************@***.***   TW
http://223.200.***.**:44388/login    ************@***.***   TW   … (38 total)

Only 7 domains did not hit; we assess their FortiGate credentials are registered under other domains or subsidiaries, or that Hudson Rock did not index them — a small number of exceptions. Comparing the attacker’s per-domain row counts against Hudson Rock’s credential counts, the two roughly agree across sectors:

SectorList rowsHR leaked credentials
Security-service provider3338
IT managed-service provider1818
Telecom operator2613
Media77
Restaurant group96
Network-equipment maker65
Management consultancy65
ICS / SCADA45

Given the strong overlap between the list and the Taiwan subset of FortiBleed, together with the content and timing of the attacker’s posts, we assess with high confidence that this event is secondary distribution by an initial access broker (IAB) who obtained the FortiBleed leak.

Impact assessment and recommendations

To reiterate: the sample contains no credentials or connection addresses, and a hit in the Hudson Rock dataset only means the domain appeared in the FortiBleed credential set — it does not mean the organization was breached or currently faces risk. For the same reason, this report does not publish the affected domains individually; we recommend that every organization using FortiGate SSL-VPN assume it or its supply chain may be on the list and self-audit per the guidance below.

For organizations using FortiGate SSL-VPN or whose supply chain involves related services, we recommend:

  • Immediately rotate credentials for external-facing SSL-VPN and management interfaces, especially where a service or managed relationship touches a FortiGate environment;
  • Confirm FortiOS is upgraded to a PBKDF2-based version, and reset passwords after upgrading to remove any residual SHA-256 hashes;
  • Enable phishing-resistant MFA across the board and reduce management-interface exposure;
  • Diff the current FortiGate configuration against a known-good backup to confirm there are no unknown admin accounts, VPN users, newly exposed management interfaces, or unexpected policy, local-in policy, trusted-hosts, or other unauthorized changes;
  • If the FortiGate integrates with AD/LDAP, RADIUS, or other centralized identity providers, treat the bound accounts as potentially exposed: review their authentication records on domain controllers and other systems, and check for password reuse;
  • Review firewall, VPN, and domain-controller logs for anomalous logins, going back at least to mid-June 2026 and, where log retention allows, extending across the relevant Fortinet incident and the device’s potential exposure window;
  • For individual-device FortiBleed exposure, self-check via Hudson Rock’s FortiBleed lookup page.

References

MITRE ATT&CK mapping

TacticTechniqueProcedure
Credential accessT1110.001FortiBleed's online logon attempts against weak-password, MFA-less FortiGate devices (Fortinet calls it brute-force)
Credential accessT1110.002Offline cracking of salted SHA-256 hashes from the leaked config data (per Beaumont)
Resource developmentT1650Potential buyers can purchase or acquire existing enterprise network access from Roiese
Initial accessT1078Anticipated abuse where a buyer logs in with valid accounts after obtaining credentials
Initial accessT1133Anticipated abuse gaining initial access via SSL-VPN or external remote services

Indicators of compromise

TypeIndicatorFirst seenLast verifiedConfidenceStatus
MD59989693bbc6e4142d60fd379aaffc9f5Taiwan Sample Access.txt: the leak-list sample file provided by the attacker2026-07-172026-07-24High
URLhxxps://t[.]me/Rois_DataAttacker Telegram channel (RoisData)2026-07-172026-07-24HighACTIVE
URLhxxp://darkfoxaqhfpxkrbt7vxns2z2u2k72sgmqbzeorupaiottw3ecm2wgyd[.]onion/User-RoieseDarkForums (Tor hidden service) seller profile page for Roiese2026-07-172026-07-24HighACTIVE

OIS-2026-008 · TLP:CLEAR under FIRST TLP 2.0 · Cite this research with its report ID and permalink.