A campaign against Fortinet equipment compromises tens of thousands of systems
Researchers cited by Reuters described a large-scale campaign against Fortinet firewall and VPN devices that allegedly compromised tens of thousands of systems and facilitated credential theft.

News summary
Researchers cited by Reuters described a large-scale campaign against Fortinet firewall and VPN devices that allegedly compromised tens of thousands of systems and facilitated credential theft.
Perimeter devices are high-priority assets: inventory, versions, configuration, backups, and alerts regarding administrative access are essential.
Source: Reuters — 27 July 2026
What happened
Researchers cited by Reuters described a large-scale campaign targeting Fortinet firewall and VPN devices, said to have compromised tens of thousands of systems and enabled credential theft. The attack relied on perimeter devices exposed to the internet, a common entry point into corporate networks.
Unlike the social-engineering cases, here the target was the network equipment itself, exploiting its exposure and, presumably, unpatched versions or misconfigurations.
What it teaches about exposed network equipment
Firewalls and VPNs are the gateway into the network and, precisely for that reason, a priority target. A campaign of this scale shows that leaving a perimeter device unpatched or misconfigured is like leaving the front door unlocked.
Credentials stolen in this type of campaign are later used to access other systems, so the impact can extend well beyond the initial attack if access is not rotated and reviewed.
What to review
Priorities for any organisation with Fortinet or similar perimeter equipment:
- An up-to-date inventory of firewalls and VPNs, with firmware version and patch status.
- Priority application of security updates published by the vendor.
- Alerts on unusual administrative access to these devices.
- Credential rotation and review of active sessions after any vulnerability advisory.
Frequently Asked Questions
- What type of devices were affected?
- Fortinet firewall and VPN devices exposed to the internet, according to the research cited by Reuters.
- How many systems are estimated to have been compromised?
- Tens of thousands, according to the researchers cited in the report.
- What should a company with this type of equipment do?
- Keep it updated as a priority and review its administrative access with the same care as the rest of the critical infrastructure.
Concepts mentioned in this article: Backup · Firewall
This type of news demonstrates that cybersecurity, cloud, and business continuity must be planned together. Seintec can help you achieve this in your organisation; contact us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.