# Massive Credential-Harvesting Campaign Compromises Over 30,000 Fortinet Devices Worldwide


A sweeping credential-harvesting campaign has successfully extracted working login credentials from more than 30,000 Fortinet devices across nearly 200 countries, representing one of the largest coordinated attacks against network security infrastructure in recent years. Security researchers have identified active targeting across multiple sectors, with threat actors compiling comprehensive lists of compromised credentials for immediate exploitation.


## The Threat


The scale of this credential-harvesting operation underscores a fundamental vulnerability in how organizations deploy and maintain network security appliances. Fortinet FortiGate firewalls and VPN concentrators—core infrastructure components protecting sensitive networks—have become prime targets for attackers seeking to establish persistent access into enterprise environments.


Key metrics of the campaign:

  • 30,000+ compromised devices with harvested working credentials
  • Nearly 200 countries represented among affected organizations
  • Multiple sectors targeted including finance, healthcare, government, and technology
  • Active exploitation already underway using harvested credentials

  • The threat actors have moved beyond simple reconnaissance; they now possess validated, functional credentials that bypass standard authentication mechanisms. This represents a critical escalation from detection to weaponization.


    ## Background and Context


    About Fortinet and Its Role in Network Security


    Fortinet FortiGate products dominate enterprise network perimeter defense. These appliances serve as:

  • Primary firewall and gateway solutions for most organizations
  • VPN concentrators handling secure remote access
  • Intrusion prevention systems (IPS) protecting internal networks
  • Primary chokepoints for enforcing security policies across organizations

  • FortiGate devices are not peripheral to enterprise security—they are foundational. Compromise of these devices provides attackers with:

  • Direct access to internal network traffic
  • Ability to intercept VPN connections
  • Visibility into user behavior and data flows
  • Potential foothold for lateral movement

  • Historical Context


    This incident follows a well-established pattern of targeting network infrastructure:

  • 2022-2023: CVE-2022-41328 (FortiOS authentication bypass) saw widespread exploitation
  • 2024: Multiple zero-day vulnerabilities in FortiGate products discovered and exploited
  • Ongoing: Persistent interest from state-sponsored and criminal threat actors in FortiGate compromise

  • Network appliances represent "crown jewel" targets because they sit at the intersection of access and visibility—a position that makes them invaluable to attackers seeking to establish persistent, difficult-to-detect presence within organizations.


    ## Technical Details


    Attack Methodology


    Security researchers tracking this campaign have identified several vectors through which credentials may have been harvested:


    | Attack Vector | Mechanism | Detection Difficulty |

    |---------------|-----------|---------------------|

    | Brute force attacks | Systematic attempts against weak or default credentials | Low (generates logs) |

    | Credential stuffing | Reused credentials from other breaches tested against FortiGate devices | Medium (mixed with legitimate traffic) |

    | Exploiting known vulnerabilities | Authentication bypass vulnerabilities to extract credentials without valid login | High (exploitation leaves minimal traces) |

    | Social engineering | Phishing targeting administrators to capture credentials | Medium (depends on awareness training) |

    | Malware/infostealer | Malicious software capturing credentials from administrator workstations | High (post-compromise) |


    The Credential Compilation


    What distinguishes this campaign from typical reconnaissance efforts is the compilation of working credentials—not just discovered usernames or password lists, but confirmed valid authentication tokens. This indicates:


  • Attackers have validated each credential against live FortiGate instances
  • They understand which credentials provide administrative versus standard user access
  • They have organized credential repositories for rapid deployment during attacks
  • The harvested credentials are immediately actionable rather than theoretical

  • ## Implications


    Immediate Risks for Affected Organizations


    Organizations with Fortinet devices should assume potential compromise and face several categories of risk:


    1. Unauthorized access to internal networks through compromised VPN credentials or firewall admin accounts

    2. Man-in-the-middle (MITM) attacks intercepting encrypted traffic passing through compromised appliances

    3. Configuration manipulation allowing attackers to disable logging, create backdoors, or modify security rules

    4. Lateral movement using compromised firewall access to attack internal systems

    5. Data exfiltration through network appliance access providing visibility into all network traffic


    Affected Sectors


    The breadth of targeting suggests a threat actor operating with minimal sector specialization—potentially a criminal marketplace where compromised credentials are being traded or sold. However, organizations in the following sectors should elevate response priority:


  • Finance and banking (high-value transaction data and authentication systems)
  • Healthcare (patient data and operational technology access)
  • Government and defense (classified systems and state actor interest)
  • Technology and SaaS (intellectual property and customer data)
  • Critical infrastructure (energy, utilities, water systems)

  • Market for Compromised Credentials


    The existence of organized credential lists suggests a functioning marketplace where:

  • Compromised credentials are being sold to other threat actors
  • Criminal groups are purchasing access rather than conducting their own reconnaissance
  • Ransomware operators may be acquiring entry points for large-scale campaigns
  • Nation-state actors may be establishing persistent infrastructure

  • ## Recommendations


    Immediate Actions (Within 24 Hours)


  • Assume compromise: Begin investigation assuming FortiGate devices have been targeted
  • Check access logs: Review FortiGate authentication logs for unauthorized login attempts and successful connections
  • Change administrative credentials: Force password reset for all FortiGate administrative accounts across all devices
  • Enable MFA: Implement multi-factor authentication on all FortiGate admin interfaces if not already deployed
  • Isolate suspicious devices: Any FortiGate showing signs of unauthorized access should be isolated from production traffic pending forensic analysis

  • Short-term Response (1-2 Weeks)


  • Conduct forensic analysis: Engage incident response specialists to examine FortiGate configuration changes and logs
  • Verify firewall rules: Audit all firewall policies to identify any unauthorized rules or backdoors
  • Review VPN activity: Analyze VPN connection logs for anomalous access patterns or unauthorized users
  • Patch and update: Apply the latest security patches for all FortiGate devices
  • Monitor outbound traffic: Implement detection for command-and-control (C2) communication patterns

  • Long-term Hardening (Ongoing)


  • Implement network segmentation: Reduce reliance on perimeter security by segmenting internal networks
  • Deploy anomaly detection: Use behavioral analytics to identify unauthorized activities on FortiGate devices
  • Establish baseline configurations: Maintain immutable records of authorized FortiGate configurations to detect tampering
  • Rotate credentials regularly: Implement 90-day password rotation for administrative accounts
  • Consider hardware appliance inventory: Evaluate whether all deployed FortiGate devices are still necessary or if some can be retired

  • ## HackWire Analysis


    This credential-harvesting campaign represents a critical inflection point in how enterprise security infrastructure is attacked. Historically, attackers spent months or years maintaining access through compromised endpoint devices or obscured malware. Now, credential theft offers immediate, validated entry points with minimal detection risk—a threat actor can simply log in like an authorized administrator.


    The geographic scope (200 countries) and apparent sector-agnostic targeting suggests this is less a surgical espionage operation and more a systematic infrastructure grab-and-monetize scheme. Compromised Fortinet credentials are valuable to anyone seeking network access: ransomware gangs, data thieves, corporate espionage groups, and nation-state operators are all likely purchasers or end-users of these credentials.


    What makes this particularly dangerous is that FortiGate compromise is exceptionally difficult to detect after initial access. Unlike ransomware that announces itself through encrypted files, or malware that generates detectable network traffic, an attacker with valid administrative credentials on a firewall can operate entirely within expected system parameters. They can review logs before deleting them, modify rules without raising alerts, and position themselves for months before launching a destructive attack.


    For defenders, the hard lesson is this: perimeter security appliances are no longer perimeter defenses against external attackers—they are now points of compromise that enable attackers to become internal. Organizations need to operate under the assumption that their firewalls may already be compromised, which means security strategy cannot rely on the perimeter being trustworthy. This demands zero-trust architecture, microsegmentation, encrypted traffic inspection, and behavioral anomaly detection at layers far deeper than the firewall.


    The next 30-60 days will likely see a surge in ransomware attacks, data breaches, and targeted espionage operations leveraging these compromised credentials. Organizations that do not immediately verify their FortiGate device integrity face extreme risk.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)