Key Takeaways:
- A database of over 86,644 working credentials for Fortinet FortiGate firewalls from 194 countries has been discovered.
- The attack, dubbed FortiBleed, relies on automated scanning, past password leaks, and VPN traffic sniffing rather than a zero-day vulnerability.
- Victims include governments (over 111 domains), telecoms, and major corporations (over 20% are enterprises with >$1B in revenue).
The cybersecurity world has been shaken by a new, active campaign named FortiBleed. SOCRadar researchers have uncovered a server belonging to a hacking group that contained a massive database of over 86,000 verified, working usernames and passwords for Fortinet FortiGate network security devices. If your organization relies on these solutions, your network might already be compromised.
How Were the Firewalls Compromised?
Interestingly, unlike many high-profile attacks from the past, FortiBleed does not exploit a 0-day vulnerability. The attack is largely based on poor security hygiene and full automation:
- Hackers scan the internet for FortiGate devices.
- They test a database of known, previously leaked passwords, hoping that administrators havenât changed them (which proves to be a highly effective strategy).
- After a successful login, they use the compromised device as a listening post to passively monitor SSL VPN traffic, intercepting more passwords transmitted over the network and fueling the attack cycle.
The vast majority of compromised accounts are default administrator and system accounts whose names and passwords were never changed since installation.
The Massive Scale and Geopolitical Backdrop
The list of victims spans organizations from almost every industry across 194 countries. It is particularly alarming that the telecommunications sector (over 5,600 devices) and government institutions (591 entries across 111 domains) have been heavily targeted. The countries with the highest number of compromised devices are India and the United States, but the attack has reached virtually every corner of the globe.
Clues such as target selection, the tools used, and the infrastructure strongly suggest that Russian-speaking cybercriminals are behind the attack. Targeting NATO member states and government facilities implies that the operation has geopolitical motives alongside financial ones.
How to Protect Your Network?
If your organization uses Fortinet devices, you must act immediately:
- Change all passwords: Refresh credentials for all administrative and VPN accounts, especially those that havenât been changed in a long time.
- Enable 2FA: Two-factor authentication should be an absolute requirement for any account with remote access.
- Restrict panel access: The firewallâs administrative panel should never be directly accessible from the public internet.
- Update software: Ensure that the firmware on your device has the latest security patches.