Skip to main content

A campaign against Fortinet equipment compromises tens of thousands of systems

Researchers cited by Reuters described a large-scale campaign against Fortinet firewall and VPN devices that allegedly compromised tens of thousands of systems and facilitated credential theft.

CybersecuritySeintec Team2-3 min read
A campaign against Fortinet equipment compromises tens of thousands of systems

News summary

Researchers cited by Reuters described a large-scale campaign against Fortinet firewall and VPN devices that allegedly compromised tens of thousands of systems and facilitated credential theft.

Perimeter devices are high-priority assets: inventory, versions, configuration, backups, and alerts regarding administrative access are essential.

Source: Reuters — 27 July 2026

What happened

Researchers cited by Reuters described a large-scale campaign targeting Fortinet firewall and VPN devices, said to have compromised tens of thousands of systems and enabled credential theft. The attack relied on perimeter devices exposed to the internet, a common entry point into corporate networks.

Unlike the social-engineering cases, here the target was the network equipment itself, exploiting its exposure and, presumably, unpatched versions or misconfigurations.

What it teaches about exposed network equipment

Firewalls and VPNs are the gateway into the network and, precisely for that reason, a priority target. A campaign of this scale shows that leaving a perimeter device unpatched or misconfigured is like leaving the front door unlocked.

Credentials stolen in this type of campaign are later used to access other systems, so the impact can extend well beyond the initial attack if access is not rotated and reviewed.

What to review

Priorities for any organisation with Fortinet or similar perimeter equipment:

  • An up-to-date inventory of firewalls and VPNs, with firmware version and patch status.
  • Priority application of security updates published by the vendor.
  • Alerts on unusual administrative access to these devices.
  • Credential rotation and review of active sessions after any vulnerability advisory.

Frequently Asked Questions

What type of devices were affected?
Fortinet firewall and VPN devices exposed to the internet, according to the research cited by Reuters.
How many systems are estimated to have been compromised?
Tens of thousands, according to the researchers cited in the report.
What should a company with this type of equipment do?
Keep it updated as a priority and review its administrative access with the same care as the rest of the critical infrastructure.

Concepts mentioned in this article: Backup · Firewall

This type of news demonstrates that cybersecurity, cloud, and business continuity must be planned together. Seintec can help you achieve this in your organisation; contact us.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.