FortiBleed leaks 73,000 Fortinet VPN logins
A security researcher discovered an exposed database containing login credentials for more than 73,000 Fortinet and FortiGate VPN devices, in plaintext, according to BleepingComputer. Big names show up in the data, including Chevron, Samsung, Toyota, and AT&T.
The attackers reportedly ran billions of password-guessing attempts against FortiGate VPNs, the boxes companies use to let employees connect securely from outside the office. Once a password worked, they grabbed login session data, cracked it with a cluster of graphics cards, and used the credentials to move deeper into company networks. They also left behind details on each victim's industry, revenue, and headcount, information that reads like a target list for follow-up attacks.
This is not a new software flaw. It is the result of weak or reused passwords being ground down at industrial scale, then the spoils left sitting on an open server for anyone to find.
What to do: If your organization uses a FortiGate VPN, assume your credentials may already be in this leak. Reset every VPN password today and require MFA, a second verification step beyond a password, for all VPN logins. If you are an individual employee, change your VPN password now and report any suspicious login alerts to your IT team immediately.
Sources

