Last updated 1 month ago
Fortinet, a global cybersecurity company, is the target of a sweeping credential-harvesting campaign affecting over 30,000 of its devices across nearly 200 countries. The attack was publicly disclosed in June 2026, though the exact discovery date is not specified. The campaign has already compiled a list of working credentials for tens of thousands of compromised devices, indicating a significant and ongoing threat to organizations using Fortinet products.
The attack chain involves the exploitation of vulnerabilities in Fortinet devices, allowing threat actors to harvest credentials. The specific CVE identifiers are not mentioned in the article, but the method is consistent with known vulnerability exploitation. The attackers have targeted various sectors globally, and the compromised data includes credentials that could be used for further unauthorized access. No specific threat actor or ransomware group has been attributed to this campaign.
No post-incident details such as regulatory actions, litigation, ransom payments, or breach notifications are provided in the article. The focus remains on the active exploitation and the scale of the compromise.
Attackers exploited vulnerabilities in Fortinet devices to harvest credentials
Fortinet's failure to secure its devices against known vulnerabilities allowed attackers to harvest credentials from over 30,000 devices globally. This highlights the need for timely patch management and robust credential hygiene, especially for organizations in the technology sector. The scale of the attack underscores the importance of continuous monitoring and vulnerability scanning to detect and remediate exploited devices promptly.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector