PROFILE: FortiBleed — The Russian Group That Compromised 270 Belgian Organizations Without Them Knowing
On June 23, 2026, Belgian cybersecurity firm Secutec published an alert that shook Belgium's institutional and professional world: a cybercriminal group linked to Russia had compromised at least 270 organizations across Belgium. Local governments, law firms, schools, businesses — their systems had been infiltrated since February 2026. For months, the attackers had moved freely
- On June 23, 2026, Belgian cybersecurity firm Secutec published an alert that shook Belgium's institutional and professional world: a cybercriminal group linked to Russia had compromised at least 270 organizations across Belgium. Local governments, law firms, schools, businesses — their systems had been infiltrated since February 2026. For months, the attackers had moved freely
- PROFILE: FortiBleed — The Russian Group That Compromised 270 Belgian Organizations Without Them Knowing
- Introduction: A silent Russian cyberattack at the heart of Belgium
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
PROFILE: FortiBleed — The Russian Group That Compromised 270 Belgian Organizations Without Them Knowing
Introduction: A silent Russian cyberattack at the heart of Belgium
The Secutec alert of June 23, 2026 — when silence becomes an open wound
On June 23, 2026, Belgian cybersecurity firm Secutec published an alert that shook Belgium's institutional and professional world: a cybercriminal group linked to Russia had compromised at least 270 organizations across Belgium. Local governments, law firms, schools, businesses — their systems had been infiltrated since February 2026. For months, the attackers had moved freely through their networks without anyone noticing.
The operation, designated under the codename FortiBleed in security analyses, exploited a vulnerability in Fortinet's partner portal — one of the world's most widely deployed firewall manufacturers. By accessing this portal, the Russian hackers were able to steal more than 110 million credentials and compromise 75,000 firewalls worldwide. Belgium was just one of many victims. But its institutional exposure — and the presence of numerous organizations linked to NATO and the EU on its soil — made it a particularly attractive target.
Not a spectacular attack — a patient, methodical infiltration
What characterizes the FortiBleed operation is not its brutality but its patience. This is not an attack that destroys and announces itself. It is a silent, methodical infiltration designed to persist as long as possible inside targeted systems. In at least 45 systems among the Belgian victims, the hackers created new user accounts to ensure persistent access — even if the initial vulnerability was subsequently patched.
This modus operandi is characteristic of actors linked to Russian intelligence services: the objective is not always to destroy or paralyze — it is to collect, monitor, position. Read communications. Map networks. Identify sensitive personnel. Prepare future operations. This is a war of intelligence, not a war of sabotage. And that is precisely why it is so difficult to detect and so dangerous to underestimate.
Portrait of the attack: how FortiBleed operated
The Fortinet vulnerability — exploiting the weakest link in the chain
The vulnerability exploited by FortiBleed targeted not the Fortinet firewalls themselves, but the company's partner portal — the online platform that resellers and commercial partners use to manage licenses, configurations, and technical support. By compromising this portal, the hackers gained access to a trove of information about Fortinet installations worldwide: access credentials, network configurations, and administrator contact information.
This is a classic supply chain attack approach — targeting not the final victim directly, but a trusted intermediary that provides access to it. This method was popularized by the SolarWinds attack of 2020, considered one of the most devastating intrusions in cybersecurity history. FortiBleed follows the same blueprint: compromise the software supply chain to reach thousands of targets simultaneously through a single initial attack vector.
110 million credentials, 75,000 firewalls — the global scale of the operation
FortiBleed's scale extends far beyond Belgium. The numbers are staggering: 110 million credentials stolen and 75,000 firewalls compromised worldwide. These firewalls protect the networks of corporations, government institutions, hospitals, universities, and military organizations. Each compromised firewall represents a potential entry point into the very network it is supposed to protect.
For Secutec and the cybersecurity experts who analyzed the operation, the purpose of this mass of data is not immediately clear — but several hypotheses impose themselves: global mapping of targeted organizations, identification of priority targets for future operations, access to sensitive communications for intelligence operations, or the establishment of backdoors activatable at a strategic moment of Moscow's choosing.
Belgium as a privileged target — why Brussels interests Moscow
The headquarters of NATO, the EU, and hundreds of international organizations
Belgium is not a random target in the Russian cyberespionage arsenal. It is home to NATO's headquarters, the European Union's headquarters, hundreds of diplomatic missions, defense think tanks, international security agencies, and dozens of companies working on sensitive contracts with these organizations. Infiltrating Belgian networks means potentially accessing information about strategic decisions of the Atlantic Alliance and European institutions.
This institutional proximity has made Belgium a prime hunting ground for Russian intelligence services for decades. Long before cyberwar, Russian agents were active in Brussels collecting intelligence on NATO and the EU. The shift to cyber did not change the objective — it changed the tools, the scale, and the speed. FortiBleed is simply the 2026 version of an intelligence strategy as old as the Cold War.
The 270 Belgian victims: municipalities, lawyers, schools
Among the 270 Belgian organizations identified as compromised, the diversity of targets is itself revealing. Among them are local governments — cities, municipalities, regional administrations — that manage citizens' personal data, urban infrastructure, and crisis plans. There are law firms, some of which work on sensitive cases linked to disputes with Russian actors or matters touching on strategic interests. And there are educational institutions, which serve as access vectors into broader networks.
For cybersecurity experts, this diversity of targets is not contradictory — it is strategically coherent. Organizations with low cyber-defense capacity (municipalities, schools) are often used as pivot points to reach better-protected organizations with which they communicate. A compromised municipality can be the starting point for an attack on a regional security agency. A compromised law firm can expose the confidential communications of a client working for NATO.
The modus operandi of Russian hackers — patience, persistence, depth
Creating persistent accounts — a survival technique inside compromised systems
In at least 45 of the compromised Belgian systems, FortiBleed's hackers did not only exfiltrate data — they created new user accounts, securing permanent network access independent of the initial vulnerability that had opened the door. This technique — known as persistence establishment — is one of the hallmarks of advanced persistent threat (APT) actors linked to nation-states.
Its principle is simple but formidable: once inside the system, the actor builds an access infrastructure that will survive security patches, password resets, and even software updates. The created account looks like a legitimate account. It can pass unnoticed in routine audits. And it guarantees the attacker permanent access — for months, even years — until a deep forensic investigation detects it.
Since February 2026: months of invisible presence inside Belgian networks
One of the most troubling aspects of the Secutec alert is its temporal dimension. The infiltration of Belgian organizations reportedly began in February 2026. The alert was not published until June 2026. Four months of invisible presence, during which the Russian hackers could read, copy, map, and position themselves freely inside the compromised systems. Four months of collected intelligence. Four months of preparation for potential future operations.
This gap between intrusion and detection is unfortunately common in the cybersecurity world. Industry studies indicate that the mean time to detect an advanced intrusion is 200 days or more. This means that for every attack detected within weeks, there are dozens that persist for six months, a year, sometimes longer. FortiBleed in Belgium is not an exception. It is the invisible norm of contemporary cyberwar.
The group behind FortiBleed — actors linked to Russian intelligence
The hallmarks of a Russian state APT
Attributing a cyberattack is always complex and rarely absolute. But the FortiBleed operation presents several characteristic markers of APT (Advanced Persistent Threat) groups linked to Russian intelligence services: the technical sophistication of the attack vector, the strategic selection of targets (heavy concentration on NATO member states), the persistence technique of account creation, and the apparent objective of long-term intelligence collection rather than immediate sabotage.
These characteristics match the profiles of well-documented Russian groups such as APT29 (Cozy Bear) and Sandworm, affiliated respectively with the SVR (Foreign Intelligence Service) and the GRU (military intelligence). These groups have a long history of operations against Western targets: the compromise of the US Democratic National Committee in 2016, the attacks against Ukrainian infrastructure in 2017, the SolarWinds affair in 2020, and many more.
The link with the war in Ukraine — the cyber campaign as a parallel front
FortiBleed did not happen in a vacuum. It is part of a systematic Russian cyber campaign directed against countries supporting Ukraine. Belgium, as NATO's host nation and an active EU member backing Kyiv, is a natural target in that strategy. Intelligence collected on Belgian networks can feed Russian strategic decision-making on the Ukraine war — providing information on allied positions, planned weapons deliveries, and ongoing diplomatic discussions.
More broadly, Russia's cyber campaign against the West is the third front of the war in Ukraine — after the military front and the economic sanctions front. Russia, aware of its limitations on the first two fronts, is investing massively in cyberwar to compensate: destabilizing allied institutions, collecting intelligence, preparing sabotage options for potential future escalations, and maintaining permanent psychological pressure on Western governments and populations.
Belgium's response and its allies — adequate, insufficient, or both?
Secutec, the alert, and emergency measures
Secutec's alert on June 23, 2026 triggered an emergency response across affected organizations. Security teams were mobilized to audit accesses, close suspicious accounts, apply available patches, and strengthen monitoring of compromised networks. The Centre for Cybersecurity Belgium (CCB) was involved in coordinating the national response.
But an emergency response, however professional, cannot erase months of hacker presence inside compromised systems. Data that may have been exfiltrated cannot be recovered. Communications that may have been read cannot be retroactively disavowed. The persistent accounts created in the 45 identified systems may have planted secondary access points not yet discovered. The response is necessary. It is insufficient on its own.
What Belgium must do — and what NATO must demand
The FortiBleed incident highlights structural gaps in the cybersecurity of Belgian organizations: lack of continuous network access monitoring, excessive dependence on third-party solutions without thorough security auditing, and the absence of an early-detection protocol adapted to APT threats. These gaps are not unique to Belgium — they are common to most Western administrations and small to mid-sized institutions.
What Belgium must do is invest massively in cyber hygiene training, regular security audits, and public-private partnerships with firms like Secutec that have the expertise to detect advanced intrusions. What NATO must demand from its members is a minimum level of cyber resilience proportional to the sensitivity of information processed in host countries. Because if Belgian networks are compromised, it is potentially the entire Atlantic Alliance that is exposed.
The broader context: the epidemic of Russian cyberattacks against NATO
Void Blizzard, UNC6508, GREYVIBE — Russia's cyber actors proliferate
FortiBleed is not an isolated incident. In June 2026, the international cybersecurity community documented an unprecedented wave of Russian and Chinese cyber operations against NATO member states and their allies. The group Void Blizzard had been running campaigns against member states since April 2024. A suspected operator of this group, Denis Obrezko, was arrested in Thailand and indicted in the United States on June 10, 2026.
In the same month, Google revealed the UNC6508 campaign (China) that had infiltrated American and Canadian medical, academic, and military institutions. The firm WithSecure documented the group GREYVIBE, a Russian-language actor using generative AI tools (ChatGPT, Gemini) to generate sophisticated phishing campaigns against Ukraine. And the Five Eyes published on June 22, 2026 a joint warning about state actors' use of AI to reshape offensive cyber capabilities.
An invisible war with no front line
Cyberwar has no visible front line. It has no map on which to track territorial gains and losses. It has no daily human casualty counts to shock consciences. But it is real, it is permanent, and it affects millions of ordinary citizens — in their municipalities, their law offices, their schools — without them being aware of it. That may be its deepest danger: the invisibility that breeds indifference.
That indifference is the terrain on which operations like FortiBleed thrive. As long as citizens, businesses, and institutions don't perceive cyberwar as a concrete threat to their daily security, cybersecurity investments will remain insufficient. As long as policymakers treat cyber defense as a secondary budget line, Russian hackers will continue to map our networks with impunity.
What FortiBleed reveals about Russian strategy beyond Ukrainian battlefields
Russia is using cyberwar to compensate for its military failures
Russia's strategy in Ukraine has suffered significant setbacks. The initial offensive on Kyiv failed in March 2022. The Donbas front advances at the cost of colossal human losses for limited territorial gain. Economic sanctions are eroding Russia's industrial base. In this context, cyberwar offers Moscow a domain where its investment is asymmetrically effective: a few dozen specialized hackers can cause disproportionate damage to hundreds of organizations across dozens of countries.
This imbalance between cost and impact is what makes the Russian cyber threat so attractive from a strategic standpoint. An operation like FortiBleed — which compromised 270 Belgian organizations and 75,000 firewalls worldwide — likely required a team of a few dozen specialists, a limited budget, and a few months of work. The cost-effectiveness ratio is incomparable to that of any conventional military operation.
Dormant capability — backdoors for future crises
One aspect of FortiBleed deserving particular attention is what experts call dormant capability: the persistent access points created in the 45 identified systems may not be intended for immediate use. They may be strategic assets held in reserve for a future escalation — a major geopolitical crisis, a direct military confrontation between NATO and Russia, or an escalation scenario in which Moscow would want to strike allied targets in depth.
Under this interpretation, the 270 compromised Belgian organizations are not merely passive intelligence victims — they are forward positions in a hybrid warfare infrastructure prepared for the future. This reading, taken seriously by cybersecurity analysts, implies a response that goes beyond simple detection and remediation: it implies a comprehensive cleansing effort across all potentially compromised systems, thorough forensic auditing, and a structural overhaul of security practices.
Toward collective cyber defense — lessons of FortiBleed for NATO and the EU
Sharing threat intelligence — a reflex that isn't yet automatic
On the same topic
ESSAY: Fourth Heat Wave — Europe Enters the Age…
On July 28, 2026, the New York Times reports that the…
COMMENTARY: A Supermarket in Chernihiv — the Normalization of…
On the night of July 27 to 28, 2026 , the…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
One of FortiBleed's most important lessons is the need for rapid threat intelligence sharing between organizations, sectors, and NATO member countries. Secutec published its alert in June 2026 — but how long before information about the Fortinet vulnerability had circulated in closed cybersecurity circles? How many organizations could have protected themselves if information sharing had been faster, broader, more systematic?
The EU has made progress in this area with the NIS2 Directive, which imposes incident notification obligations on operators of essential infrastructure. But application remains uneven. Cross-sector collaboration between private and public actors in the cyber domain is still insufficient. And cross-border information sharing — crucial to responding to attacks like FortiBleed that simultaneously target dozens of countries — remains limited by legal obstacles and institutional reluctance.
Training as the first line of defense
In the vast majority of cases, cyberattacks exploit not sophisticated technological flaws but human errors: a click on a malicious link, a weak password, an unused account left active, a default configuration never changed. FortiBleed exploited a technical vulnerability — but persistence inside compromised systems was possible in part due to a lack of human monitoring of network access.
Investing in cyber hygiene training for all employees — from school principals to municipal civil servants, from law firm secretaries to system administrators — is the most cost-effective measure an organization can take to reduce its attack surface. It is not glamorous. It is not spectacular. But it is fundamental. And it is the only measure that can both detect and prevent the next FortiBleed before it goes unnoticed for four months.
Fortinet and the responsibility of cybersecurity providers
When the guardian becomes the breach — the accountability of security vendors
There is a profound and troubling irony at the heart of FortiBleed: Fortinet is a cybersecurity company. Its product is supposed to protect networks. That is why 75,000 organizations worldwide trust it to guard their doors. And it is precisely that trust — materialized in a poorly secured partner portal — that was turned against them. The guardian had become the breach.
This reality raises a fundamental question about the accountability of cybersecurity vendors. When a security solutions provider is itself compromised and becomes an attack vector against its customers, who is responsible? Service contracts generally shield providers from legal liability. But the ethical and reputational responsibility is another matter. Fortinet's customers have the right to demand full transparency about the extent of the compromise and the measures taken to prevent it from happening again.
Digital trust as a Western strategic asset
Beyond the Fortinet case, the FortiBleed incident raises a broader question about digital trust in the Western ecosystem. Cybersecurity rests on chains of trust: organizations trust their security vendors, vendors trust their partners, partners trust their tools. Every link in this chain is a potential attack surface.
Russia and its allies have understood this for a long time. That is why they target partner portals, software update servers, digital certificates — the elements that everyone trusts without questioning. Strengthening digital trust in the Western ecosystem requires not only better securing individual technologies, but fundamentally rethinking how we validate, audit, and supervise the entire chain of digital trust on which our institutions rest.
Dark web markets and the monetization of Russian cyberespionage
Reselling access on the dark web — FortiBleed's economic model
One of the objectives identified by Secutec in the FortiBleed operation was the resale of compromised access on the dark web. In at least 45 Belgian systems, the hackers had created persistent accounts — not only for their own use, but also to offer them to third-party buyers: other criminal groups, foreign intelligence services, or cybercrime actors seeking entry points into institutional networks.
This economic model — known as Initial Access Brokers (IAB) — has become one of the most flourishing industries in international cybercrime. Access to a government network can sell for anywhere from a few thousand to hundreds of thousands of dollars on online black markets. Russian hackers therefore have a dual incentive: state intelligence on one side, commercial monetization on the other. These two motivations reinforce each other and make the threat even more difficult to contain.
The 110 million credentials — a strategic resource for years to come
The value of the 110 million credentials stolen in the FortiBleed operation extends far beyond immediate exploitation. This data constitutes a durable strategic resource: credentials change rarely and incompletely, password patterns repeat, and personal information (names, email addresses, phone numbers) retains its value for years. FortiBleed's 110 million credentials could fuel phishing campaigns, social engineering, and credential stuffing attacks for a long time to come.
That is why cybersecurity experts recommend that affected organizations not only reset their immediate passwords, but conduct a comprehensive review of their access policy: adopting multi-factor authentication, auditing all active accounts, reviewing access privileges, and strengthening employee training on the risks of targeted phishing using stolen personal data. Because the 110 million credentials are now in circulation. And they will remain so, available, exploitable, for years.
Ukraine at the center of the target — why Kyiv is concerned by Belgian vulnerabilities
Belgian networks as a transit point toward decisions on Ukraine
To understand why Belgium is a particularly sensitive target, one must look at the flow of decisions that converge on Brussels concerning Ukraine. It is in Brussels that decisions on sanctions against Russia are made. It is in Brussels that EU military aid packages are negotiated. It is in Brussels that NATO is headquartered, where decisions on weapons deliveries, troop rotations, and collective defense plans are discussed in meetings whose content is invaluable to Moscow.
Infiltrating a Belgian network — a municipality, a law firm, a school — may seem trivial. But within the interconnected network of Brussels institutions, every compromised node is potentially a corridor toward more sensitive information. Municipal civil servants sometimes have access to regional networks connected to national networks themselves connected to allied networks. This is the six degrees of separation theory applied to cyberwar: there may be only a few hops between a suburban Brussels school and NATO's servers.
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
Zelensky, the allies, and strategic information warfare
The government of Volodymyr Zelensky has made transparency about Russian cyberattacks a conscious political strategy. By documenting and making public the Russian attacks against Ukrainian and allied infrastructure, Kyiv builds a dossier of accusation against Moscow before international opinion. Secutec's alert about FortiBleed fits into this context: every documented incident, every public attribution, weakens the Russian narrative that cyberwar is merely a Western construct.
For Ukraine, every compromised allied network is an additional motivation for its partners to invest in collective cyber defense. A Belgian government that sees its own networks compromised by Russian actors better understands the daily reality that Ukrainian institutions have lived with since 2014. This solidarity through shared vulnerability may be one of the unintended but real effects of FortiBleed: transforming Belgian victims into even more committed defenders of the Ukrainian cause.
Prospects: Russian cyberwar in 2026 and beyond
The predictable intensification of Russian cyber operations
Experts agree on one point: the Russian cyberwar against the West will intensify, not subside. The military and economic pressures that Russia faces in Ukraine push it to seek asymmetric levers of pressure against its adversaries. Cyberwar is precisely that lever: low-cost, effectively deniable, and capable of inflicting real damage on civilian and institutional targets without crossing the threshold of conventional war.
In this context, FortiBleed is not the last attack of its kind. It will be one of the first in a series that experts project will be more frequent, more sophisticated, and broader in scope in the years ahead. The Five Eyes warned in June 2026 that the integration of AI into offensive cyber capabilities would reshape the threat "in months, not years." The challenge for the West is to strengthen its defenses faster than the adversary improves its attacks.
What Belgium can do for Europe — a resilience model to build
Belgium has the opportunity, post-FortiBleed, to become a model of cyber resilience for Europe. It has the necessary assets: quality technical expertise (as shown by Secutec's work), a central institutional position (NATO and EU headquarters), and reinforced political motivation from the scale of the compromise. What it lacks is a massive, coordinated investment in cyber defense at the national and local level.
If Belgium takes FortiBleed seriously — not merely as a technical incident to manage, but as a strategic alarm signal about its systemic vulnerability — it can make it the starting point for a transformation of its national cyber architecture. A transformation that would benefit not only Brussels, but all the allies whose interests converge in the Belgian capital. Because in the twenty-first century's cyberwar, security is collective or it is nothing.
Conclusion: FortiBleed is an alert, not an isolated case
270 Belgian organizations — but how many worldwide?
The 270 Belgian organizations identified by Secutec represent only a fraction of FortiBleed's global exposure. With 75,000 firewalls compromised worldwide, Belgium is one of dozens of affected countries. Belgium was fortunate enough to have a cybersecurity firm capable of detecting and documenting the operation. How many other countries have not yet detected their own FortiBleed?
This question — without a certain answer — should sit at the center of cybersecurity discussions in every Western government. Not tomorrow. Now. Because while policymakers debate budgets and procedures, Russian hackers continue to map, position, and prepare. The threat does not pause. The response cannot either.
What FortiBleed demands of us collectively
FortiBleed demands several things of us collectively. It demands that governments invest in cyber defense commensurate with the threat — not in speeches, but in real budgets and deployed capabilities. It demands that private and public organizations take cyber hygiene as seriously as physical security. It demands that NATO and the EU strengthen their threat intelligence sharing architecture. And it demands that citizens understand that this invisible war concerns them directly.
Russia is not only bombing Kyiv. It is mapping our networks from Brussels, from Berlin, from Washington. It is preparing tomorrow's wars inside today's servers. And we, in the meantime, are still debating whether cybersecurity truly deserves a serious budget line. FortiBleed should end that debate. For good.
Balance sheet of an invisible war — what Russian cyberwar truly costs the West
The invisible cost: trust, resources, time
Beyond the stolen data and compromised access points, the FortiBleed operation carries a cost that is not easily measured: the cost of eroded trust. The 270 Belgian organizations must now ask themselves: what was read? What was exfiltrated? Which files, communications, and plans were exposed? This persistent uncertainty — this inability to know with certainty what was compromised — is itself a form of strategic damage that the attacker can claim as a win.
Added to this is the resource cost: forensic audits, system resets, cybersecurity consultants, emergency training, access policy overhauls. For a rural municipality or a small law firm, these costs are significant. For all 270 affected organizations combined, they are considerable. And for the tens of thousands of organizations affected worldwide by FortiBleed, they represent a real economic drain on Western resources — which is, precisely, one of the strategic objectives of Russian cyberwar.
Resistance as a political act — refusing to let fatigue win
Faced with the scale and continuity of the Russian cyber threat, there is a real risk: fatigue. The fatigue of defending against a permanent, invisible threat that constantly evolves. The temptation to give up, to tell oneself it's inevitable, that not everything can be controlled. That is precisely what Moscow hopes for: that the accumulation of incidents, alerts, and endless breaches will eventually normalize compromise and discourage investment in cyber defense.
Resisting that fatigue is a political act. Continuing to invest, to train, to share information, to demand vendor transparency, to support firms like Secutec that do this essential work of detection and documentation — that is refusing to let Russia win this war of digital attrition. It is defending not only our networks, but our values, our strategic autonomy, and our right to a digital life free from hostile surveillance.
By Maxime Marquette, columnist
Columnist's transparency note
Editorial positioning
I write as a pro-Ukraine columnist and advocate for Western cyber defense. This profile rests on open-source materials published by cybersecurity firms, specialized media, and government reports. Attribution to Russian actors is based on the analyses of the cited firms, not on confidential information. The complexity of attribution in cyberspace demands an epistemological caution I have attempted to observe by consistently qualifying Russian links as "linked to" rather than presenting them as absolute certainties.
Sources and limitations
The figures cited (270 organizations, 110 million credentials, 75,000 firewalls, 45 systems with persistent accounts) come from reports published by Secutec and relayed by cybersecurity media. They reflect the state of knowledge at the time of the June 23, 2026 alert. The actual scope of the operation may exceed these figures as investigations continue. I did not have access to Secutec's original technical report.
Sources
Primary sources
Secondary sources
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). PROFILE: FortiBleed — The Russian Group That Compromised 270 Belgian Organizations Without Them Knowing. MadMax. https://mad-max.co/en/article/portrait-fortibleed-le-groupe-russe-qui-a-compromis-270-organisations-belges-san
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.