# Massive Credential-Harvesting Campaign Compromises 30,000+ Fortinet Devices Across 200 Countries


Cybersecurity researchers have uncovered a sweeping, ongoing credential-harvesting campaign targeting Fortinet security appliances across nearly 200 countries, with attackers already stockpiling valid credentials for tens of thousands of compromised devices. The attack represents a significant breach of perimeter security infrastructure deployed by enterprises worldwide, potentially exposing internal networks to downstream exploitation and lateral movement.


## The Threat


Attackers are actively harvesting login credentials from Fortinet FortiGate firewalls, FortiProxy appliances, and other Fortinet security products through large-scale scanning and credential compromise. The attackers have already compiled a database of working credentials for 30,000+ devices, according to threat intelligence reports. These credentials provide direct administrative access to the devices—effectively handing attackers the keys to the perimeter defenses of thousands of organizations.


Critical threat indicators:


  • Attackers have functioning credentials with live access confirmed across multiple devices
  • The campaign spans 197 countries, indicating either opportunistic mass targeting or a highly organized operation
  • Compromised devices include critical infrastructure and enterprise security appliances
  • No vendor-issued patch or authentication bypass has been publicly attributed; the compromise likely stems from weak credentials, configuration issues, or targeted credential stuffing

  • The credential database appears to be actively maintained and potentially available for sale or distribution within criminal forums, raising the specter of secondary exploitation by other threat actors.


    ## Background and Context


    Fortinet is one of the world's largest security appliance vendors, with over 600,000 FortiGate firewalls deployed globally. These devices sit at the network perimeter, protecting internal infrastructure from external threats. They are among the most critical security tools in any enterprise environment—a breach of these devices can render other security controls ineffective.


    FortiGate firewalls are ubiquitous in:

  • Enterprise networks – protecting office infrastructure
  • Data centers – controlling ingress/egress traffic
  • Cloud environments – gateway security
  • Government and defense contractors – critical infrastructure protection
  • Financial institutions – payment processing networks
  • Healthcare systems – patient data protection

  • This breadth of deployment makes Fortinet devices a high-value target. A compromised FortiGate doesn't just bypass the firewall—it provides attackers with:

  • Network visibility – full view of internal traffic flows
  • Man-in-the-middle capability – ability to intercept and modify traffic
  • Lateral movement – pivoting point to internal networks
  • Persistent access – ability to maintain presence even if other systems are patched

  • Fortinet has a history of high-severity vulnerabilities. In 2022-2023, critical CVEs affecting FortiGate prompted mass exploitation campaigns. However, the current campaign appears to rely on credential compromise rather than zero-days, suggesting attackers are leveraging operational weaknesses rather than unpatched flaws.


    ## Technical Details


    The attack mechanism appears to operate in phases:


    Phase 1: Enumeration and Scanning

    Attackers scan the public internet for Fortinet devices using port-scanning and banner-grabbing techniques. FortiGate appliances typically expose management interfaces on ports 80, 443, 8080, and 8443. Shodan and similar services make identifying Fortinet devices trivial—a simple search query returns thousands of exposed management interfaces.


    Phase 2: Credential Harvesting

    Once a device is identified, attackers employ:

  • Default credential attacks – many Fortinet installations retain default admin/admin or admin/fortinet credentials
  • Credential stuffing – testing known credential pairs from prior breaches (LinkedIn, Okta, other corporate databases)
  • Weak password guessing – targeting common patterns (company name, simple numbers, etc.)
  • Exploitation of API endpoints – if older firmware versions are running, some may have authentication bypass vulnerabilities

  • Phase 3: Persistence and Harvesting

    Once credentials are confirmed valid, attackers:

  • Extract additional credentials from the device
  • Document firewall rules and network topology
  • Catalog connected internal systems
  • Store credentials in a central database for later monetization or exploitation

  • The fact that 30,000+ devices have already been compromised and credentials validated suggests this campaign has been running undetected for weeks or months.


    ## Scope and Impact


    | Metric | Details |

    |--------|---------|

    | Devices Compromised | 30,000+ Fortinet appliances |

    | Geographic Reach | 197 countries |

    | Target Sectors | Enterprise, government, finance, healthcare, critical infrastructure |

    | Credential Status | Active, validated credentials with live access |

    | Attack Pattern | Ongoing; no indication of campaign cessation |


    The geographic distribution across 197 countries indicates this is not a targeted operation focused on a specific sector or region. Instead, this appears to be indiscriminate mass harvesting—attackers scanning broadly and compromising whatever they find.


    Organizations in every region and vertical should assume exposure is possible.


    ## Implications


    For Organizations:


    1. Immediate breach of perimeter defense – Any organization using Fortinet appliances may have compromised administrative credentials already documented by attackers.


    2. Delayed exploitation risk – Attackers may not immediately exploit stolen credentials. Instead, they may sell access, hold it for future campaigns, or wait until defenders' attention wanes before moving laterally.


    3. Supply chain visibility – Fortinet devices are often managed by managed service providers (MSPs) and IT service providers. A compromise at the MSP level could affect hundreds of downstream customers.


    4. Regulatory exposure – Organizations in regulated industries (finance, healthcare, government) face mandatory breach notifications and compliance violations if attacker access enabled data exfiltration.


    ## Recommendations


    Immediate Actions (This Week):


  • Audit Fortinet administrative access – Force password resets on all Fortinet devices
  • Review access logs – Check for unauthorized admin logins, especially from unexpected geographies
  • Update firmware – Patch to the latest stable Fortinet firmware to close known authentication bypass vulnerabilities
  • Change default credentials – Ensure no device retains manufacturer default credentials
  • Implement MFA – Enable multi-factor authentication on all FortiGate administrative interfaces

  • Short-Term Actions (This Month):


  • Network segmentation – Restrict management traffic to Fortinet devices to specific admin IP ranges
  • Enhanced logging – Enable detailed audit logging on all Fortinet devices; send logs to a central SIEM for anomaly detection
  • Intrusion detection tuning – Update IDS signatures to detect suspicious FortiGate management activity
  • Credential rotation cycle – Implement quarterly credential rotation for sensitive network appliances
  • Vendor communication – Contact Fortinet support to understand if your organization's devices were among the compromised list

  • Long-Term Security Posture:


  • Hardware security modules (HSM) – Consider deploying HSM-backed credential management for critical appliances
  • Zero-trust principles – Assume appliances may be compromised; implement defense-in-depth strategies that don't rely solely on perimeter security
  • Threat intelligence subscriptions – Subscribe to feeds that monitor for credential breaches affecting your organization's infrastructure

  • ---


    ## HackWire Analysis


    This campaign exemplifies a critical shift in attacker methodology: rather than racing to develop zero-day exploits, threat actors are operating at massive scale against low-hanging fruit. When 30,000+ devices can be compromised through default credentials and weak password hygiene, the incentive to develop sophisticated exploits evaporates.


    What makes this different: This isn't a high-profile ransomware gang or nation-state actor—it's likely a criminal organization running an industrial-scale credential harvesting operation, possibly monetizing access through initial access broker (IAB) marketplaces. The breadth across 197 countries and all sectors suggests the attackers are agnostic about target value; they're simply harvesting at scale and selling to the highest bidder.


    The pattern here matters. In 2023-2024, we've seen similar campaigns against:

  • Cisco ASA firewalls (unpatched default credentials)
  • Palo Alto Networks PAN-OS devices (authentication bypass)
  • Okta instances (credentials from breach databases)

  • Each time, the common thread is the same: attackers don't need advanced capabilities when enterprises still run outdated firmware, retain default credentials, or reuse compromised passwords. The industry-wide failure to enforce baseline hygiene creates an attacker subsidy.


    What defenders are missing: Most organizations will patch Fortinet firmware and reset passwords. But the real risk is *downstream access*. If an attacker has valid credentials and network visibility from a FortiGate, they can:

  • Monitor encrypted traffic in plaintext (SSL inspection)
  • Modify firewall rules to exfiltrate data
  • Document internal network topology for espionage
  • Maintain persistence through subtle configuration changes that survive reboots

  • Organizations should assume that if their credentials were harvested, attackers already understand their internal network layout. Defenders need to focus on detecting lateral movement and data exfiltration, not just credential rotation.


    Immediate question for every CISO: Do you have the logging and monitoring in place to detect if an attacker *using your own valid credentials* is moving through your network? Most organizations cannot answer this affirmatively.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)