# Massive Credential-Harvesting Campaign Compromises 30,000+ Fortinet Devices Across 200 Countries
Cybersecurity researchers have uncovered a sweeping, ongoing credential-harvesting campaign targeting Fortinet security appliances across nearly 200 countries, with attackers already stockpiling valid credentials for tens of thousands of compromised devices. The attack represents a significant breach of perimeter security infrastructure deployed by enterprises worldwide, potentially exposing internal networks to downstream exploitation and lateral movement.
## The Threat
Attackers are actively harvesting login credentials from Fortinet FortiGate firewalls, FortiProxy appliances, and other Fortinet security products through large-scale scanning and credential compromise. The attackers have already compiled a database of working credentials for 30,000+ devices, according to threat intelligence reports. These credentials provide direct administrative access to the devices—effectively handing attackers the keys to the perimeter defenses of thousands of organizations.
Critical threat indicators:
The credential database appears to be actively maintained and potentially available for sale or distribution within criminal forums, raising the specter of secondary exploitation by other threat actors.
## Background and Context
Fortinet is one of the world's largest security appliance vendors, with over 600,000 FortiGate firewalls deployed globally. These devices sit at the network perimeter, protecting internal infrastructure from external threats. They are among the most critical security tools in any enterprise environment—a breach of these devices can render other security controls ineffective.
FortiGate firewalls are ubiquitous in:
This breadth of deployment makes Fortinet devices a high-value target. A compromised FortiGate doesn't just bypass the firewall—it provides attackers with:
Fortinet has a history of high-severity vulnerabilities. In 2022-2023, critical CVEs affecting FortiGate prompted mass exploitation campaigns. However, the current campaign appears to rely on credential compromise rather than zero-days, suggesting attackers are leveraging operational weaknesses rather than unpatched flaws.
## Technical Details
The attack mechanism appears to operate in phases:
Phase 1: Enumeration and Scanning
Attackers scan the public internet for Fortinet devices using port-scanning and banner-grabbing techniques. FortiGate appliances typically expose management interfaces on ports 80, 443, 8080, and 8443. Shodan and similar services make identifying Fortinet devices trivial—a simple search query returns thousands of exposed management interfaces.
Phase 2: Credential Harvesting
Once a device is identified, attackers employ:
Phase 3: Persistence and Harvesting
Once credentials are confirmed valid, attackers:
The fact that 30,000+ devices have already been compromised and credentials validated suggests this campaign has been running undetected for weeks or months.
## Scope and Impact
| Metric | Details |
|--------|---------|
| Devices Compromised | 30,000+ Fortinet appliances |
| Geographic Reach | 197 countries |
| Target Sectors | Enterprise, government, finance, healthcare, critical infrastructure |
| Credential Status | Active, validated credentials with live access |
| Attack Pattern | Ongoing; no indication of campaign cessation |
The geographic distribution across 197 countries indicates this is not a targeted operation focused on a specific sector or region. Instead, this appears to be indiscriminate mass harvesting—attackers scanning broadly and compromising whatever they find.
Organizations in every region and vertical should assume exposure is possible.
## Implications
For Organizations:
1. Immediate breach of perimeter defense – Any organization using Fortinet appliances may have compromised administrative credentials already documented by attackers.
2. Delayed exploitation risk – Attackers may not immediately exploit stolen credentials. Instead, they may sell access, hold it for future campaigns, or wait until defenders' attention wanes before moving laterally.
3. Supply chain visibility – Fortinet devices are often managed by managed service providers (MSPs) and IT service providers. A compromise at the MSP level could affect hundreds of downstream customers.
4. Regulatory exposure – Organizations in regulated industries (finance, healthcare, government) face mandatory breach notifications and compliance violations if attacker access enabled data exfiltration.
## Recommendations
Immediate Actions (This Week):
Short-Term Actions (This Month):
Long-Term Security Posture:
---
## HackWire Analysis
This campaign exemplifies a critical shift in attacker methodology: rather than racing to develop zero-day exploits, threat actors are operating at massive scale against low-hanging fruit. When 30,000+ devices can be compromised through default credentials and weak password hygiene, the incentive to develop sophisticated exploits evaporates.
What makes this different: This isn't a high-profile ransomware gang or nation-state actor—it's likely a criminal organization running an industrial-scale credential harvesting operation, possibly monetizing access through initial access broker (IAB) marketplaces. The breadth across 197 countries and all sectors suggests the attackers are agnostic about target value; they're simply harvesting at scale and selling to the highest bidder.
The pattern here matters. In 2023-2024, we've seen similar campaigns against:
Each time, the common thread is the same: attackers don't need advanced capabilities when enterprises still run outdated firmware, retain default credentials, or reuse compromised passwords. The industry-wide failure to enforce baseline hygiene creates an attacker subsidy.
What defenders are missing: Most organizations will patch Fortinet firmware and reset passwords. But the real risk is *downstream access*. If an attacker has valid credentials and network visibility from a FortiGate, they can:
Organizations should assume that if their credentials were harvested, attackers already understand their internal network layout. Defenders need to focus on detecting lateral movement and data exfiltration, not just credential rotation.
Immediate question for every CISO: Do you have the logging and monitoring in place to detect if an attacker *using your own valid credentials* is moving through your network? Most organizations cannot answer this affirmatively.
— HackWire Editorial
---
## Related Coverage