FortiBleed: 86,644 Fortinet Devices Compromised, and Most of Them Just Had the Locks Left On
CISA is urging Fortinet customers to lock down their FortiGate firewalls and VPNs after a credential-harvesting campaign, dubbed FortiBleed, compiled a working database of more than 86,644 logins across 194 countries, according to SecurityWeek. That's roughly half of all internet-facing Fortinet devices worldwide.
The campaign, believed to involve Russian-speaking attackers, didn't need anything fancy. Per BleepingComputer, generic admin accounts made up 35% of stolen credentials and built-in factory accounts made up another 28%. Translation: more than six in ten compromised logins existed because someone never bothered to change the default password or rotate it after setup. The rest came from accounts created by individual organizations, meaning attackers got in some other way too.
Security researcher Kevin Beaumont confirmed with affected organizations that the stolen logins still work and are fairly recent. With valid credentials to a firewall or VPN, an attacker effectively has the keys to the building's front gate.
What to do: If your organization runs a FortiGate device, assume your credentials are in that database. Rotate every password tied to it today, disable any default or factory accounts you haven't touched, and check your login logs for sign-ins from unfamiliar locations.

