New! Try the FREE Predictive Security Plugin for WordPress – Scan, Secure & Stay Safe in Seconds!

Current CyberSecurity Advisories

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Release date
13 July 2026
Alert rating
HIGH

Description

Our advice & guidance covers a broad range of topics

Audience

Cyber security professionalsLarge organisationsPublic sector

Current update

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.


What has happened?

Fortinet firewalls and VPN gateways have been targeted as part of a global campaign, with some indications of potential impact in the UK.

A database of credentials has been leaked by a threat actor following brute-force, dictionary and credential stuffing attempts against internet-facing FortiGate and VPN portals.  

Credential stuffing is a method where attackers use passwords stolen from one web service to try to access accounts on other services, taking advantage of any reuse of username and password combinations.


Who is affected?

Organisations using these products should prioritise investigating whether they have been affected and, as soon as possible, follow mitigation advice to help defend against the threat.

Use one of the FortiBleed asset checkers for any domains that may have been affected: 


What should I do?

UK organisations using Fortinet edge devices with SSL VPN enabled should investigate potentially malicious activity on the device and monitor their network for unusual activity.

Fortinet has published a blog post providing guidance and an analysis.

The priority actions should be:

  1. Check SOCRadar’s FortiBleed Checker or Hudson Rock’s FortiBleed Checker for any domains that are not listed in their Early Warning asset list.
  2. Confirm whether the device exists and belongs to you.
  3. Determine if your Fortinet device is compromised by looking for common Indicators of Compromise (IoC), including unauthorised account creation, and unexpected activity in log files. (See: Technical Tip: Collect Indicators of Compromise (IoC))
  4. If evidence of compromise exists, isolate the device from the internet and your internal network.
  5. If you believe you have been compromised, and are in the UK, you should report it and consider using an assured Cyber Incident Response provider. You can also report the compromise to the vendor to assist their investigation.
  6. Factory reset the device, as changing credentials alone may not be sufficient if threat actors have obtained persistence on the device (see: Technical Tip: How to reset to Factory Default configuration). Ensure you have obtained logs, configs and other artefacts from the device useful for investigations which will be destroyed during the factory reset process.
  7. Investigate other edge devices that share credentials with the compromised device.
  8. Investigate devices reachable by the compromised device and monitor firewall logs for suspicious activity in order to obtain assurance that onward compromise within your network has not occurred.
  9. Harden the re-commissioned system including:
    • Ensure management interfaces are not exposed to the internet.
    • Update to the latest version.
    • Remove out of support systems as soon as possible.
    • Change all default, generic, or reused administrator passwords.
    • Ensure multi-factor authentication (also known as 2-step verification) is enforced on all VPN and device management logins.
    • Enable PBKDF2 for admin interface and enforce all admins re-login to the device (see: Technical Tip: Enforcing PBKDF2 as hash function for administrator accounts

Published

Publish date

News type

Alert

Protect your assets with Predictive