Global Cyberattack Compromises Thousands of Fortinet Devices

A large-scale cyberattack has recently affected tens of thousands of Fortinet firewalls and virtual private network VPN) devices used by companies around the world. Cybersecurity researchers have discovered that hackers are gaining access to these systems through stolen or leaked passwords rather than using new software vulnerabilities.
The attack campaign, known as FortiBleed, was identified by cybersecurity firms Hudson Rock and SOCRadar. According to their findings, cybercriminals are using automated tools to scan the internet for exposed Fortinet devices. Once they locate a device, they attempt to log in using credentials that have already been leaked or obtained from previous security incidents.
Global Cyberattack Compromises Thousands of Fortinet Devices
Unlike many cyberattacks that rely on exploiting unknown weaknesses in software, this campaign takes advantage of poor password security. Many organizations appear to be using weak passwords or failing to change credentials that may have been exposed in the past. This makes it easier for attackers to gain unauthorized access to critical network devices.
After successfully compromising a firewall or VPN, hackers can monitor network traffic and collect additional login credentials passing through the system. These newly obtained passwords are then used to attack more devices, creating a cycle that allows the campaign to spread further. Security experts describe this process as self-sustaining because every successful compromise provides new opportunities for additional attacks.
Fortinet has acknowledged the reports and stated that the campaign is not linked to any recent vulnerability in its products. According to the company, the attackers are mainly using previously exposed data and password brute-forcing techniques. This means that the threat comes from poor credential management rather than flaws in the devices themselves.
Researchers estimate that the number of compromised devices is significant. Hudson Rock reported evidence suggesting that more than 73,000 Fortinet-related URLs may have been affected. Meanwhile, SOCRadar estimated that over 30,000 devices have been compromised. Although the exact number remains uncertain, both reports indicate that the campaign is widespread.
Several well-known global companies were reportedly found among the affected organizations, including Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC. However, most of these companies have not publicly commented on the claims.
See Also: 13 Million Records at Risk in Suspected Adobe Cyberattack – How to Protect Yourself
The countries with the highest number of affected devices include India, the United States, Taiwan, and Mexico. Victims have been identified across many industries, including information technology services, telecommunications, and construction. Government organizations have also reportedly been impacted.
Security researchers believe the group behind the attacks may be Russian-speaking, although no official attribution has been confirmed. The campaign first gained attention after security researcher Bob Diachenko reported the discovery of a large database containing Fortinet-related credentials. Independent researcher Kevin Beaumont later reviewed the data and confirmed that it appeared to be genuine.
The FortiBleed campaign highlights the importance of strong cybersecurity practices. Organizations should regularly update passwords, enable multi-factor authentication, and monitor internet-facing systems for unauthorized access. Even advanced security devices can become vulnerable when basic password security measures are ignored.
Mobile Phone Taxes Portal
Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.
Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).
Explore NowFollow us on Google News!