Key findings
- This is an initial access broker (IAB) secondary-distribution event in which a seller using the alias Roiese is offering network access to 96 Taiwanese enterprises on the DarkForums dark web forum and Telegram, sourced from the June 2026 FortiBleed credential leak.
- The sample the attacker provided contains only "domain + revenue + employee band" and no FortiGate URLs, credentials, IPs, or passwords; the sample alone cannot prove any organization was breached and should be treated as attacker-claimed exposure, not a confirmed event.
- Cross-referencing the 96 domains against Hudson Rock's public FortiBleed dataset, 89 hit (92.7%, compared 2026-07-24), supporting the assessment that the list originates from FortiBleed.
- The list spans listed manufacturers, telecom, media, retail, shipping and logistics, and biotech and medical, and includes several security / IT managed-service providers; if the latter are exposed at the perimeter, the risk spills over to their clients through managed relationships — a supply-chain risk.
- The Roiese account was newly registered in June 2026 and is filled with FortiBleed-related sale posts; we assess it to be an access broker monetizing the leak rather than a long-established threat entity.
- We recommend that organizations whose supply chain touches the affected domains immediately rotate the relevant credentials, confirm FortiOS has moved to PBKDF2 and removed old hashes, and enable phishing-resistant MFA to cut off password-spray abuse.
On 17 July 2026, a seller on Telegram calling themselves “I’m Rois” posted a message explicitly tagging “Taiwan” as the target and offered a file, Taiwan Sample Access.txt, for prospective buyers to preview. After FTV News reporter Su En-min covered the event on 23 July 2026 under the headline “Exclusive: Hackers Target Taiwan! 90 Companies Named, Nearly 20 Listed Firms Caught in a Security Storm,” it spread rapidly across Taiwan’s security community. This report investigates the event, which we designate the “Roiese” leak.
Important caveat: The list of enterprises described here consists of targets unilaterally claimed by the attacker. The sample the attacker provided contains no FortiGate URLs, credentials, IPs, or passwords, and the sample alone cannot prove that any enterprise was breached or currently faces risk. To avoid causing secondary harm to unverified parties, this report does not publish individual enterprises or domains; for any concern, defer to each organization’s official statement.
FortiBleed background
This event stems from the large-scale FortiBleed credential leak of mid-June 2026. Security researcher Volodymyr “Bob” Diachenko found an exposed server during scanning that held a large volume of valid Fortinet VPN credentials — usernames, emails, and plaintext passwords — totaling 73,932 firewall URLs and 21,632 domains across 194 countries. Hudson Rock and researcher Kevin Beaumont sampled and verified the data as genuine, and the case was named “FortiBleed.”
Unlike Heartbleed, this is not a zero-day. Fortinet attributes it mainly to reuse of credentials leaked in prior incidents (FG-IR-26-060, FG-IR-25-647) and brute-forcing of devices with weak passwords and no MFA. The key weakness is credential storage: only from FortiOS 7.2.11/7.4.8/7.6.1 did it switch to PBKDF2, so on devices upgraded from older versions where the administrator never re-logged in, passwords remained as salted SHA-256, easy to crack offline. Beaumont, however, notes that the IPs in this dataset largely do not overlap with the 2025 Belsen Group leak, judges it not to be repackaged old data, and remains skeptical of Fortinet’s “purely reused existing credentials” framing.
Taiwan had 3,637 devices in the dataset, third globally after India and the United States, with IT services the most affected sector. CISA issued an alert on 18 June, urging organizations to terminate all SSL VPN and admin sessions and reset passwords, confirm PBKDF2 adoption and remove old hashes, review firewall, VPN, and domain-controller logs, enable phishing-resistant MFA, and reduce management-interface exposure.
Attacker distribution
In this event, the seller operated under the name “Roiese” on the dark web forum DarkForums and a public Telegram channel, and on 17 July 2026 posted leak intelligence about Taiwan, offering Taiwan Sample Access.txt for prospective buyers to preview. No indicators of a completed sale have been observed.

A closer look at DarkForums shows the account was newly registered in late June 2026, with posts concentrated on multiple FortiBleed-related access listings from the same period. We assess it to be an access-broker account created to monetize this leak, not a long-established threat entity. A check of Chinese-language underground markets found no related listings.

File analysis
Per the attacker’s sample, there are 282 total rows, 96 unique domains after deduplication, and 186 duplicates; each row follows the fixed format domain revenue <revenue> <employee-band> Employees Taiwan.
By sector, the list spans listed manufacturers (electronics contract manufacturing/assembly, panels and optoelectronics, semiconductors, precision machinery and motion control, materials and chemicals), telecom, media and live-streaming, retail and shopping malls, shipping and logistics, and biotech and medical devices, down to SMEs and religious/arts organizations; employee sizes range from 5000+ to 1-10. Notably, the list also includes several security / IT managed-service providers; if such vendors are exposed at the perimeter, the risk spills over to their clients through managed relationships — the supply-chain dimension that most warrants attention in this event.
Sourcing and cross-verification
The list itself contains no Fortinet artifacts, so whether it originates from FortiBleed cannot be self-evidenced from the sample and must be cross-checked against an authoritative external dataset. We used Hudson Rock’s Fortinet leak dataset as the baseline; on comparison (2026-07-24), 89 of the 96 domains hit (92.7%), each accompanied by a redacted FortiGate login address and FortiGuardID. Taking the security-service provider with the most rows in the list (33) as an example, it maps to roughly 38 redacted login addresses in the Hudson Rock dataset:
http://220.130.***.***:4433/login ************@***.*** TW
https://114.32.***.***/login ************@***.*** TW
http://223.200.***.**:44388/login ************@***.*** TW … (38 total)
Only 7 domains did not hit; we assess their FortiGate credentials are registered under other domains or subsidiaries, or that Hudson Rock did not index them — a small number of exceptions. Comparing the attacker’s per-domain row counts against Hudson Rock’s credential counts, the two roughly agree across sectors:
| Sector | List rows | HR leaked credentials |
|---|---|---|
| Security-service provider | 33 | 38 |
| IT managed-service provider | 18 | 18 |
| Telecom operator | 26 | 13 |
| Media | 7 | 7 |
| Restaurant group | 9 | 6 |
| Network-equipment maker | 6 | 5 |
| Management consultancy | 6 | 5 |
| ICS / SCADA | 4 | 5 |
Given the strong overlap between the list and the Taiwan subset of FortiBleed, together with the content and timing of the attacker’s posts, we assess with high confidence that this event is secondary distribution by an initial access broker (IAB) who obtained the FortiBleed leak.
Impact assessment and recommendations
To reiterate: the sample contains no credentials or connection addresses, and a hit in the Hudson Rock dataset only means the domain appeared in the FortiBleed credential set — it does not mean the organization was breached or currently faces risk. For the same reason, this report does not publish the affected domains individually; we recommend that every organization using FortiGate SSL-VPN assume it or its supply chain may be on the list and self-audit per the guidance below.
For organizations using FortiGate SSL-VPN or whose supply chain involves related services, we recommend:
- Immediately rotate credentials for external-facing SSL-VPN and management interfaces, especially where a service or managed relationship touches a FortiGate environment;
- Confirm FortiOS is upgraded to a PBKDF2-based version, and reset passwords after upgrading to remove any residual SHA-256 hashes;
- Enable phishing-resistant MFA across the board and reduce management-interface exposure;
- Diff the current FortiGate configuration against a known-good backup to confirm there are no unknown admin accounts, VPN users, newly exposed management interfaces, or unexpected policy, local-in policy, trusted-hosts, or other unauthorized changes;
- If the FortiGate integrates with AD/LDAP, RADIUS, or other centralized identity providers, treat the bound accounts as potentially exposed: review their authentication records on domain controllers and other systems, and check for password reuse;
- Review firewall, VPN, and domain-controller logs for anomalous logins, going back at least to mid-June 2026 and, where log retention allows, extending across the relevant Fortinet incident and the device’s potential exposure window;
- For individual-device FortiBleed exposure, self-check via Hudson Rock’s FortiBleed lookup page.
References
- Hudson Rock, “FortiBleed — 73,932+ compromised Fortinet firewalls,” https://www.hudsonrock.com/fortinet
- K. Beaumont, “FortiBleed — 75k Fortinet firewalls have admin passwords cracked,” DoublePulsar, 2026-06-17
- Carl Windsor, “Analysis of Reported Credential Compromise of FortiGate Devices,” Fortinet PSIRT, 2026-06-19
- CISA, “CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure,” Alert, 2026-06-18, https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
- Hsiao-Li Chen, “FortiBleed exposes credential data from 70,000+ Fortinet devices, with Taiwan third worst-hit globally,” iThome, 2026-06-18 (in Chinese)
MITRE ATT&CK mapping
| Tactic | Technique | Procedure |
|---|---|---|
| Credential access | T1110.001 | FortiBleed's online logon attempts against weak-password, MFA-less FortiGate devices (Fortinet calls it brute-force) |
| Credential access | T1110.002 | Offline cracking of salted SHA-256 hashes from the leaked config data (per Beaumont) |
| Resource development | T1650 | Potential buyers can purchase or acquire existing enterprise network access from Roiese |
| Initial access | T1078 | Anticipated abuse where a buyer logs in with valid accounts after obtaining credentials |
| Initial access | T1133 | Anticipated abuse gaining initial access via SSL-VPN or external remote services |
Indicators of compromise
| Type | Indicator | First seen | Last verified | Confidence | Status |
|---|---|---|---|---|---|
| MD5 | 9989693bbc6e4142d60fd379aaffc9f5Taiwan Sample Access.txt: the leak-list sample file provided by the attacker | 2026-07-17 | 2026-07-24 | High | — |
| URL | hxxps://t[.]me/Rois_DataAttacker Telegram channel (RoisData) | 2026-07-17 | 2026-07-24 | High | ACTIVE |
| URL | hxxp://darkfoxaqhfpxkrbt7vxns2z2u2k72sgmqbzeorupaiottw3ecm2wgyd[.]onion/User-RoieseDarkForums (Tor hidden service) seller profile page for Roiese | 2026-07-17 | 2026-07-24 | High | ACTIVE |