Web_Logo
Remote Support
Security Alert: FortiBleed Campaign Targets Fortinet VPN Devices
Home » Security Alerts  »  Security Alert: FortiBleed Campaign Targets Fortinet VPN Devices

Security Alert: FortiBleed Campaign Targets Fortinet VPN Devices

A large-scale credential theft campaign known as “FortiBleed” has exposed verified administrator credentials for more than 73,000 Fortinet FortiGate firewalls and VPN gateways across 194 countries. Both the US Cybersecurity and Infrastructure Security Agency (CISA) and the UK’s National Cyber Security Centre (NCSC) have issued advisories urging organisations to act immediately.

  • What it is: Attackers have been systematically harvesting and cracking credentials from internet-facing Fortinet FortiGate devices. The campaign exploits weak password hashing inherited from older FortiOS versions, combined with credentials leaked from previous Fortinet-related breaches.
  • Who is affected: Any organisation running an internet-facing Fortinet firewall or FortiGate VPN gateway — particularly devices that have not been patched or had passwords changed since earlier Fortinet incidents.
  • What the risk is: Attackers with valid admin credentials can access your network perimeter, intercept VPN traffic, and harvest additional credentials from connected users — a self-sustaining breach cycle.
  • What to do:
    • Update FortiOS to the latest version immediately on all internet-facing devices.
    • Reset all administrator and VPN user passwords on FortiGate devices.
    • Review VPN and admin logs for unexpected logins or unusual activity.
    • Enable multi-factor authentication on the management interface if not already active.

If your business uses a Fortinet firewall or VPN and you are unsure whether you are at risk, we recommend contacting your IT provider for an immediate review. Sources: CISA Advisory, NCSC Advisory.