York Computer logo York Computer
Managed IT & Security
Cybersecurity News

FortiBleed: 30,000+ Fortinet Firewalls Compromised With Old Passwords — Check Yours This Week

York Computer

Researchers at SOCRadar and Hudson Rock disclosed this week that a hacking crew has quietly built a working database of admin and VPN logins for tens of thousands of Fortinet firewalls — no zero-day required. They simply scanned the internet for exposed FortiGate devices and logged in with passwords leaked in previous breaches that the owners never bothered to change. If your business uses a Fortinet firewall or SSL VPN to let employees work remotely, your perimeter may already be wide open.

What happened

Two cybersecurity firms — SOCRadar and Hudson Rock — published findings this week on an active campaign they're calling FortiBleed. Cybercriminals have compromised tens of thousands of Fortinet firewalls and VPNs used by major companies all over the world, and the campaign does not involve abusing any unknown vulnerability — rather a more basic issue: companies may not be changing passwords to the firewall, or making sure that the credentials they use for sensitive systems exposed on the internet are not already known by hackers.

The attacker's database contains login credentials for more than 30,791 devices belonging to companies and government organizations across 194 countries. These are not random guesses. These are verified, working usernames and passwords, tested and confirmed by the attackers themselves using automated tools running around the clock. Hudson Rock's separate analysis puts the number of affected Fortinet URLs even higher — over 73,000.

Independent cybersecurity researcher Kevin Beaumont said in a blog post that he analyzed the data and confirmed it is legitimate.

Why this is bad for small businesses specifically

Fortinet firewalls are everywhere in the SMB space — they're a common pick for any office that needs a real firewall and a VPN for remote workers. That's exactly the deployment under attack.

The attack is self-feeding. The attackers scan the internet for Fortinet devices, try a curated list of known passwords against each one, and record every successful login. Once a device is compromised, they use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself.

Worse, the password list is not random — it is a carefully assembled collection of credentials leaked from Fortinet devices in earlier incidents, meaning many targets may have never changed their passwords after a prior breach. Translation: if your firewall password is the same one you set up three years ago, an attacker probably already has it on a list and is trying it right now.

Generic admin accounts and built-in Fortinet system accounts together make up the majority of compromised credentials, pointing directly to a widespread failure to rename default accounts or rotate factory credentials.

What your IT provider should be doing this week

This is a managed-IT hygiene story, not a glamorous zero-day story. If you have an MSP, they should already be on this. If you don't — or if you're not sure — here's the checklist a competent provider is running right now as part of our managed IT services lineup:

Change all admin and VPN account passwords on every Fortinet device, especially if those passwords have not been changed in the past few years. Enable two-factor authentication on every admin and remote-access account, so that even if an attacker has your password, it makes it far harder to log in.

Review login history for any access that looks unfamiliar — unusual times, unknown locations, or accounts that should not be active. And restrict management access: the firewall's admin panel should not be reachable directly from the public internet. If it is, restrict it immediately.

If there's any sign your device was hit, treat it as fully compromised — do not simply change the password; the attacker may have deployed persistent backdoors or sniffers. That means a full configuration rebuild and a hunt for anything the attacker may have left behind.

SOCRadar rates this campaign Critical and says if your organization uses a Fortinet firewall or VPN product and appears in this dataset, you should treat your network perimeter as already compromised and act immediately.

Fortinet's response

Fortinet is pushing back on the framing. A Fortinet spokesperson told TechCrunch the company is aware of the reported third-party credential-harvesting campaign, and based on the company's analysis, the data involved is a resharing of data from previous incidents as well as bruteforcing of credentials, and is not related to any recent incident or advisory.

That's technically correct and operationally irrelevant. The bad guys have working logins to tens of thousands of firewalls. Whether those logins came from a brand-new zero-day or a 2022 breach you forgot about doesn't matter to the attacker — and shouldn't matter to you. Rotate the credentials, lock down the management interface, and turn on MFA.

What York Businesses Should Do

If your York County business runs a FortiGate firewall or uses Fortinet SSL VPN for remote workers, this week is the week to rotate every admin and VPN password and confirm MFA is on. If you're not sure who owns that checklist for your office, that's exactly the gap York Computer fills as your digital bodyguard.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles