Web_Logo
Remote Support
Security Alert: 75,000 Fortinet Firewall Logins Compromised
Home » Security Alerts  »  Security Alert: 75,000 Fortinet Firewall Logins Compromised

Security Alert: 75,000 Fortinet Firewall Logins Compromised

Cybercriminals are actively selling administrator login credentials for approximately 75,000 Fortinet FortiGate firewall and VPN devices. The credentials appear to have been recently harvested and are being offered for sale online. If your business uses Fortinet equipment, this warrants immediate attention.

  • What it is: A threat actor is selling working administrator credentials for tens of thousands of Fortinet FortiGate devices, including VPN gateways and web management interfaces. The credentials are described as current and active.
  • Who is affected: Businesses running Fortinet FortiGate firewalls or SSL VPN appliances, particularly those with management interfaces accessible from the internet.
  • What is the risk: If your device credentials are among those compromised, attackers could gain admin access to your network firewall or VPN, allowing them to reconfigure security rules, intercept traffic, or establish persistent access inside your network.
  • What to do immediately: Change administrator passwords on all Fortinet devices. Disable VPN and management interfaces from internet exposure where not required. Enable multi-factor authentication on all admin accounts. Review device logs for any unexpected access over recent weeks.

If you are an OzComm client running Fortinet equipment, contact us so we can assist with a credential rotation and exposure review.