A large-scale Fortinet credential campaign has reportedly exposed access data associated with tens of thousands of VPN and firewall devices across the globe. Security researchers say the operation targeted internet-facing Fortinet systems and collected credentials tied to major corporations, government agencies, and critical infrastructure organizations.
The findings highlight the continuing value of network edge devices to cybercriminals, especially as attackers increasingly rely on stolen credentials instead of deploying traditional malware.
Researchers Link Campaign to Thousands of Devices
Researchers investigating the activity discovered evidence suggesting that attackers harvested credentials connected to approximately 75,000 Fortinet devices. The affected systems span more than a dozen countries and include organizations operating in both the public and private sectors.
Among the reported victims are Fortune 500 companies and government entities. The campaign’s scale has raised concerns because Fortinet appliances often serve as gateways into corporate environments. Access to those systems can provide attackers with a direct route into internal networks.
Researchers described the operation as one of the larger credential-focused campaigns involving Fortinet infrastructure in recent years.
Attackers Continue to Exploit Stolen Access
Unlike many cyber campaigns that rely on newly discovered vulnerabilities, this activity appears heavily focused on obtaining and leveraging credentials. Security experts have increasingly warned that valid account access has become one of the most valuable assets in the cybercrime ecosystem.
Stolen credentials allow threat actors to blend into legitimate network traffic and avoid many traditional security controls. Once inside an environment, attackers can conduct reconnaissance, access sensitive information, and establish long-term persistence.
The approach also reduces the need for complex exploits, making credential theft an attractive tactic for both financially motivated groups and state-backed operators.
Fortinet Says Activity Is Not Linked to a New Vulnerability
Fortinet acknowledged the reports but stated that the campaign does not appear connected to a newly discovered security flaw. According to the company, the exposed credentials may originate from older compromises rather than a recent breach affecting Fortinet products.
That distinction is important because organizations often focus heavily on patching software vulnerabilities while overlooking credential hygiene. Old usernames and passwords can remain valuable to attackers when accounts stay active or authentication controls remain weak.
The situation demonstrates how previously exposed credentials can continue creating risk long after the original incident has faded from attention.
Security Teams Face Renewed Pressure
The reported campaign serves as a reminder that perimeter devices remain attractive targets for cybercriminals. VPNs and firewalls frequently hold privileged access to critical business systems, making them high-value assets during intrusion attempts.
Security professionals recommend reviewing VPN accounts, rotating credentials, enforcing multi-factor authentication, and monitoring for suspicious login activity. Organizations should also verify that internet-facing infrastructure remains properly configured and fully updated.
As attackers continue shifting toward identity-based attacks, protecting access credentials has become just as important as defending against software vulnerabilities.
Conclusion
The Fortinet credential campaign demonstrates how stolen access data can create security risks on a massive scale. Researchers say the operation involved credentials linked to roughly 75,000 devices and affected organizations across multiple countries. While Fortinet maintains that the activity is not tied to a new vulnerability, the campaign highlights a growing reality for defenders: valid credentials often provide attackers with the easiest path into enterprise networks.


0 responses to “Fortinet Credential Campaign Exposes Major Organizations”