FortiBleed: over 30,000 valid Fortinet credentials found in attacker hands
SOCRadar reports an active credential-compromise campaign against Fortinet FortiGate firewalls and VPN gateways. The attacker infrastructure holds 30,791 verified working credentials spanning 21,108 unique IP addresses, 8,316 domains and 194 countries. SOCRadar says the operation is still running and that organisations appearing in the dataset should treat inclusion as a confirmed incident. Arctic Wolf separately puts the exposure at roughly 30,000 to 75,000 affected Fortinet devices, and notes FortiOS behaviour that can leave older SHA-256 administrator hashes in place after an upgrade until the administrator logs in or the password is changed.
What this means for your organisation
The firewall and VPN gateway are the front door. Working administrator credentials let an attacker rewrite rules, create their own accounts and establish durable access without exploiting a single vulnerability, and without looking abnormal in the logs. For organisations in scope of NIS2, this also becomes a reportable incident if the access has actually been used. Note that patching does not solve it: the credentials are already out.
Berigo recommends
- Rotate every administrator and VPN credential on your Fortinet estate, not only the accounts you suspect.
- Enforce multi-factor authentication for both management and VPN logins, with no service-account exemptions.
- Remove the management interface from the internet and restrict it to a defined operations network.
- Review access logs and configuration changes going back in time to establish whether the access has already been used.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch