Massive Fortinet Cyberattack Exposes 75,000 Firewall Devices Worldwide

fortinet-cyberattack-techibe.webp

Massive Fortinet Cyberattack Exposes 75,000 Firewall Devices Worldwide

In one of the biggest cybersecurity events of 2026 security researchers have reported a massive data theft campaign targeting Fortinet equipment around the world. According to published reports, attackers were able to collect login information for about 75,000 FortiGate Firewall and VPN devices many of which are used in government agencies, large enterprises, healthcare facilities and critical infrastructure.

The attack once again shows that cyber threats are not limited to software vulnerabilities, and that proper management of user identities and passwords has become one of the most important cybersecurity challenges.

What Happened in the Fortinet Cyberattack?

According to the investigation, the attackers managed to create a large database of login information for system administrators and VPN users of Fortinet devices.

Initial investigations estimated the number of affected devices at around 30,000 but subsequent investigations revealed that the campaign likely affected more than 75,000 internet-connected devices in over 190 countries.

Targeted organizations included a variety of sectors

including:

Government Entities
Banks and Financial Institutions
Hospitals and Medical Centers
Telecom Companies
Manufacturing Industries
Critical Infrastructure


Because Fortinet devices are typically located at the edge of an organization's network compromising them can pave the way for attackers to penetrate the entire internal network.

Why This Attack Is Different

Importantly, the attack was not based on a new vulnerability (Zero-Day).

Fortinet said it had not seen any evidence of a new vulnerability being exploited in its products and that the attackers were mainly exploiting credentials stolen in previous attacks password reuse and brute force attacks.

This means that even organizations that have installed all security updates are still at risk if they don't change their old passwords.

How Attackers Gained Access

Cybersecurity experts believe this campaign used a combination of several different methods:

Using stolen usernames and passwords from past data breaches
Abusing duplicate passwords
Performing brute force attacks
Extracting data from backup files or unencrypted configurations
Broadly scanning the internet for accessible Fortinet devices


Investigations also show that the attackers categorized the victims' information by country, industry, and type of organization, indicating careful planning of this operation.

Business Impact

If attackers gain access to the Fortinet appliance system administrator account they may be able to:


Change firewall security settings.
Create hidden administrative accounts.
Eavesdrop on network traffic.
Inject malware or ransomware into the network.
Steal sensitive company information.
intrude into other internal systems.


For this reason this type of attack can cause significant financial and operational losses for organizations.

What Organizations Should Do Immediately

Cybersecurity experts recommend that network administrators take the following steps as soon as possible:

Change system administrator passwords immediately
Reset VPN user logins
Enable multi-factor authentication (MFA)Restrict administrative access from the Internet
Review login logs for suspicious activity
Remove unnecessary administrative accounts
Update appliances to the latest FortiOS version


Taking these measures can significantly reduce the likelihood of similar attacks succeeding.

.Why This Matters for Enterprise Security

This attack shows that cybercriminals are more focused on digital identity theft than ever before.

In the past, attackers spent a lot of time discovering new vulnerabilities; today, many of them prefer to use leaked passwords old accounts, and weak credentials to break in.

For this reason, using unique passwords, multi-factor authentication and proper account management are as important as installing security patches.

Conclusion

This attack shows that cybercriminals are more focused on digital identity theft than ever before.

in the past, attackers spent a lot of time discovering new vulnerabilities; today, many of them prefer to use leaked passwords, old accounts, and weak credentials to break in.

For this reason, using unique passwords, multi-factor authentication, and proper account management are as important as installing security patches.

FAQs

1. What is the Fortinet cyberattack?

It is a global credential-harvesting campaign targeting Fortinet firewall and VPN devices.

2. How many devices were affected?

Researchers estimate that up to 75,000 internet-facing Fortinet devices may have been compromised.

3. Was this caused by a new vulnerability?

No. Current evidence suggests attackers relied on previously stolen credentials and password attacks rather than a newly discovered vulnerability.

4. Which organizations are at risk?

Government agencies, Fortune 500 companies, healthcare providers financial institutions, manufacturers and many other enterprises.

5. How can organizations protect themselves?

immediately rotate passwords, enable MFA, restrict administrative access, update FortiOS and continuously monitor authentication activity.

Share this article