S.MANE//SEC × AI OPS
--:--:-- UTCHARDENED
← BACK TO WIRE
BreachCRITICAL2026-06-17

Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices

Attackers have harvested credentials from over 30,000 Fortinet devices across nearly 200 countries, targeting critical sectors globally. Active exploitation suggests widespread compromise and a growing threat landscape.

// OPERATOR NOTE — S.MANE

This highlights the critical need for immediate patching and credential resets for affected Fortinet devices. Organizations should audit access logs and deploy MFA to mitigate further exploitation.

A sweeping credential-harvesting campaign has compromised over 30,000 Fortinet devices worldwide, spanning nearly 200 countries. Attackers are actively targeting critical sectors, including healthcare, finance, and government entities, to compile a substantial database of working credentials.

The attack leverages known vulnerabilities in Fortinet devices, emphasizing the importance of timely patch management. Threat actors are using these credentials to facilitate lateral movement, ransomware deployment, and data exfiltration within compromised networks.

Organizations are urged to immediately update Fortinet firmware, reset passwords, and implement multi-factor authentication (MFA). Security teams should monitor for unusual login activity and conduct thorough audits of device configurations to ensure integrity.

#Fortinet#credential-theft#global-impact#active-exploitation