Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout

June 23, 2026

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

June 23, 2026

Klue Breach Enables Hackers to Compromise Cybersecurity Firms

June 22, 2026
Facebook X (Twitter) Instagram
Tuesday, June 23
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout
News

NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout

Team-CWDBy Team-CWDJune 23, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The UK’s National Cyber Security Centre (NCSC) has released guidance for Fortinet customers impacted by a global credential theft campaign.

A database of around 75,000 credentials stolen from FortiGate firewall and SSL VPN customers was discovered by security researchers last week. Dubbed “FortiBleed,” it features usernames, email addresses and plaintext passwords for organizations including Oracle, Spotify, Toyota and AT&T.

It is understood that credentials on around half of all internet-accessible Fortinet firewalls may have been exposed in this way.

According to Hudson Rock, a firm specialized in infostealer malware, the exposed logins impact customers in 194 countries and are linked to over 21,000 unique domains.

Read more on data leaks: Exclusive: Massive IoT Data Breach Exposes 2.7 Billion Records.

It’s unclear exactly how the targeted devices were originally accessed – potentially by exploiting legacy vulnerabilities in the products, or a novel zero day.

However, it seems that the threat actors first stole configuration data and then brute-forced the passwords contained within.

The NCSC cited “brute-force, dictionary and credential stuffing attempts.”

Reports suggest many organizations have already suffered full network compromise as a result, and any organization featured in the database is at risk.

The leaked information “is formatted in a way which looks like an eCrime gang – e.g. it lists the type of company, their revenue and country,” said cybersecurity researcher, Kevin Beaumont.

“The operation’s footprint is staggering: the attackers executed an estimated 1.16 billion credential attempts against over 320,000 FortiGate targets, alongside an additional 2.1 billion brute-force attempts directed at over 160,000 MSSQL servers,” added Hudson Rock.

NCSC Guidance

The NCSC urged Fortinet customers to use Hudson Rock’s or SOCRadar’s FortiBleed checker tools to see if their devices have been affected,and then to look for indicators of compromise (IoCs) such as unauthorized account creation, or unexpected activity in log files.

It then advised impacted organizations to:

  • Isolate compromised devices from the internet and internal networks
  • Report the incident to the government and consider using an assured incident response provider
  • Obtain logs, configs and other artefacts from the device then factory reset it
  • Investigate other edge devices that share credentials with the compromised device 
  • Investigate devices reachable by the compromised device and monitor firewall logs for suspicious activity to ensure no onward compromise has occurred
  • Harden the re-commissioned system by ensuring it’s on the latest version, has strong, unique admin passwords and multi-factor authentication (MFA) applied, and is not exposed to the internet. Users should also enable PBKDF2 for the admin interface



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
Team-CWD
  • Website

Related Posts

News

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

June 23, 2026
News

Klue Breach Enables Hackers to Compromise Cybersecurity Firms

June 22, 2026
News

North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to tell if a voice call is AI or not

February 23, 2026

How cybercriminals are targeting content creators

November 26, 2025

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.