A large-scale credential theft campaign known as "FortiBleed" has compromised over 86,000 Fortinet firewall and VPN devices worldwide, including many in Australia. If your business uses a Fortinet FortiGate device for internet access or VPN, this alert applies to you.
- What it is: An automated attack campaign that scans the internet for Fortinet FortiGate firewalls, tests known passwords against each device, and records successful logins. Compromised devices are then used to intercept VPN traffic and harvest additional credentials.
- Who is affected: Organisations running Fortinet FortiGate firewalls or SSL VPN gateways — particularly those that have not changed their passwords after previous Fortinet-related security incidents. The campaign has affected devices across 194 countries.
- What the risk is: Attackers with access to your firewall can monitor all traffic passing through it, pivot into your internal network, and collect credentials for other systems.
- What action is needed: CISA issued an urgent advisory on 18 June 2026 instructing organisations to immediately terminate active sessions, reset all Fortinet VPN and administrative passwords — especially on internet-facing devices — and enforce strong password policies.
If you are an OzComm-managed client using a Fortinet device, we recommend contacting us immediately so we can review your device's exposure and assist with credential rotation.
Sources: CISA Advisory | SecurityWeek | SOCRadar