Cyber Alerts

MA-1463.062026: MyCERT Advisory - Best Practices Following Global Targeting of Fortinet Firewalls and VPN Gateways

Verified Officially confirmed

Recently, a large dataset containing credentials and configuration information associated with approximately 73,000 Fortinet VPN and firewall devices has been publicly disclosed. This dataset was collected through a campaign conducted by threat actors to obtain these credentials, while this does not appear to be linked to a newly discovered Fortinet vulnerability. The exposed data reportedly includes usernames, passwords, VPN configuration details, and other device information. Organisations whose devices have internet-facing management interfaces and credentials may be included in the leaked dataset. This may pose a risk of compromise and should prompt organisations to take immediate action to determine whether there is any evidence of unauthorised access in their organisations.

First observed
29 Jul 2026
Last checked
01 Aug 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

Recently, a large dataset containing credentials and configuration information associated with approximately 73,000 Fortinet VPN and firewall devices has been publicly disclosed. This dataset was collected through a campaign conducted by threat actors to obtain these credentials, while this does not appear to be linked to a newly discovered Fortinet vulnerability. The exposed data reportedly includes usernames, passwords, VPN configuration details, and other device information. Organisations whose devices have internet-facing management interfaces and credentials may be included in the leaked dataset. This may pose a risk of compromise and should prompt organisations to take immediate action to determine whether there is any evidence of unauthorised access in their organisations.

Why it matters

This exposed data could enable attackers to gain unauthorised access to the affected infrastructure. The attackers could passively monitor network traffic going through the devices and collect additional credentials, which then can be used to compromise more appliances.

Who is affected?

Affected products and groups

Primary Targets: Internet-facing FortiGate Firewalls (which run the FortiOS operating system) and associated SSL VPN gateways.Firmware Versions: Devices running firmware versions primarily between 7.0.14 and 7.0.16 were the focus of several threat actor scans. Older unpatched installations running FortiOS 5 and 6 are also heavily exposed.

What should you do now?

Actions from official guidance

For technical teams

  1. Terminate sessions and reset credentials. Terminate all active SSL VPN and administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.Ensure secure credential storage. Confirm your organisation’s use of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials and remove weaker legacy hashes per Fortinet’s guidance (see, Fortinet's Technical Tip: Enforcing PBKDF2 as hash function for administrator accounts in FortiOS v7.2.11 and later). Review logs. Review firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes.Enable phishing-resistant multifactor authentication (MFA). Require phishing-resistant MFA on all remote access and administrative accounts and ensure it is enforced on all external gateways and administrative interfaces.Reduce the attack surface and lock down management access. Ensure the administration of your firewall is inaccessible from the public internet; restrict Fortinet management interfaces to trusted internal networks; and remove or disable any unauthorized or unnecessary accounts. Official source

For everyone

  1. CyberSecurity Malaysia encourages users and administrators to review the security best practices and apply necessary updates. Kindly refer to the following URL: Official source
  2. Generally, CyberSecurity Malaysia advise the users of the devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied. Official source

Which sources support it?

Evidence and official sources

  1. MyCERTOfficial source
    MA-1463.062026: MyCERT Advisory - Best Practices Following Global Targeting of Fortinet Firewalls and VPN Gateways

    Recently, a large dataset containing credentials and configuration information associated with approximately 73,000 Fortinet VPN and firewall devices has been publicly disclosed. This dataset was collected through a campaign conducted by threat actors to obtain these credentials, while this does not appear to be linked to a newly discovered Fortinet vulnerability. The exposed data reportedly includes usernames, passwords, VPN configuration details, and other device information. Organisations whose devices have internet-facing management interfaces and credentials may be included in the leaked dataset. This may pose a risk of compromise and should prompt organisations to take immediate action to determine whether there is any evidence of unauthorised access in their organisations.

    Published Just published · Retrieved 01 Aug 2026