74,000 firewalls. 194 countries. Credentials confirmed working.
74,000 firewalls. 194 countries. Credentials confirmed working.
A large-scale credential compromise campaign dubbed FortiBleed has exposed validated admin credentials for approximately 74,000 Fortinet FortiGate firewalls and VPN gateways across 194 countries.
The Australian Cyber Security Centre has issued a critical alert. The data is real. Security researcher Kevin Beaumont confirmed it: “I have worked with several organisations listed, and can confirm the logins and passwords are real.”
Here’s what happened: attackers extracted configuration files from internet-facing FortiGate devices, cracked stored password hashes offline using GPU clusters, and assembled a searchable database of working credentials now circulating in cybercriminal communities.
What makes this worse? Many devices were on recent patches. Firmware updates alone weren’t enough.
This is the Zero Trust argument in one incident: don’t assume your perimeter is holding just because it’s configured correctly. Credentials expire. Configurations drift. Exposure happens at scale.
If you need help on building your Zero Trust based Cyber Resilience to reduce the risk of these kinds of attack, reach out to our team.