VORANT. Threat Intelligence Sign in Get the full feed

NCSC warns of Fortinet firewall credential leak

elevated vulnerability government-nationaltechnologyinfrastructure

A leaked credential database from brute-force and credential stuffing attacks against FortiGate/VPN portals prompts NCSC advisory for UK organisations.

The UK's NCSC has issued an alert following a global campaign targeting Fortinet firewalls and SSL VPN gateways, with indications of impact in the UK. A threat actor leaked a database of credentials obtained through brute-force, dictionary, and credential stuffing attacks against internet-facing FortiGate and VPN portals. Credential stuffing exploits password reuse across services, meaning organisations whose users reused passwords elsewhere may be at risk regardless of any software vulnerability being exploited directly.

NCSC urges organisations using Fortinet edge devices with SSL VPN enabled to investigate for potentially malicious activity, check exposed domains using FortiBleed asset checkers, and monitor networks for unusual activity. Fortinet has published its own guidance and analysis referenced in the advisory. Priority actions include credential rotation, enabling MFA, and reviewing logs for signs of unauthorised access. The NCSC also promotes its free Early Warning service to help UK organisations detect malicious activity affecting their networks sooner.

No specific CVE, malware family, or threat actor attribution is provided in this advisory; the core risk vector described is credential-based attacks (brute-force, dictionary, credential stuffing) rather than a novel software exploit. Defenders should treat this as a call to verify exposure, rotate credentials, and enforce MFA on Fortinet VPN/firewall infrastructure.

Source reporting: https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free