Skip to main content

Infinity Cloud

Fortinet Firewall & VPN Credential Exposure

Home / Fortinet Firewall & VPN Credential Exposure

Fortinet Firewall & VPN Credential Exposure

What Melbourne Businesses Need to Do Now
Just Say Hello!
Let us know more about you!





    Fortinet Firewall & VPN Credential Exposure: What Melbourne Businesses Need to Do Now

    If your business relies on a Fortinet firewall or VPN gateway, there’s an active security campaign you need to know about. It’s not a typical software bug. You can’t just wait for a patch and move on.

    What’s Happening with Fortinet Firewalls

    In June 2026, Fortinet confirmed a large-scale campaign targeting its firewalls and SSL-VPN gateways. The security community has nicknamed it “FortiBleed.” Unlike a traditional software vulnerability, this campaign is built around something far more common: stolen and reused login credentials.

    How Attackers Are Getting In

    Fortinet’s own investigation points to a simple pattern. Attackers are recycling credentials leaked in earlier, unrelated security incidents. They’re also running brute-force attempts against devices that still use weak passwords and lack multi-factor authentication (MFA).

    Once attackers have a working set of admin or VPN credentials, they don’t need to exploit any code flaw at all. They simply log in like an authorised user or administrator. From there, they can access the device — and often the wider network behind it.

     Who’s Warning Businesses About This

    Australia’s cyber security regulator, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), issued an alert on this campaign. It urges all Australian organisations using Fortinet firewall or VPN services to act immediately.

    Similar warnings have come from the US Cybersecurity and Infrastructure Security Agency (CISA) and the UK’s National Cyber Security Centre. Reports suggest tens of thousands of internet-facing devices globally may be affected.

     Why This Matters for Small and Mid-Sized Businesses

    It’s tempting to assume large-scale security campaigns like this only threaten big enterprises. In reality, small and mid-sized businesses are often more exposed, not less. Firewalls and VPNs are frequently set up once and left untouched for years. Default or reused passwords are common. MFA is often missing entirely.

    If an attacker gains access through a compromised Fortinet device, the consequences can escalate fast. They may gain unauthorised access to your internal network. They may change security settings to open the door to further attacks. Data theft and ransomware are both realistic outcomes.

    For a small business without a dedicated security team watching login activity, this kind of compromise can go unnoticed for weeks.

    What You Should Do Right Now

    Based on guidance from the ACSC, CISA, and Fortinet itself, here are the priority actions if your business uses Fortinet firewalls or VPN gateways:

    1. **Rotate all credentials immediately.** Reset every admin and VPN password, especially on internet-facing devices. End all active sessions to force re-authentication.
    2. **Turn on multi-factor authentication** for every administrator and VPN account. This single step sharply reduces the value of a stolen password to an attacker.
    3. **Patch your devices.** Keep firmware up to date. Where possible, move to Fortinet firmware versions that support stronger credential storage (PBKDF2 hashing).
    4. **Limit exposure of management interfaces.** Admin portals shouldn’t be reachable from the public internet unless there’s a specific, well-controlled reason for it.
    5. **Review your logs.** Look for unfamiliar accounts, unusual login times or locations, and unexpected configuration changes. These are common signs of prior compromise.

    The Bigger Lesson for Melbourne Businesses

    What makes this campaign notable isn’t a clever new exploit. It’s a reminder that basic credential hygiene is still one of the biggest security gaps for businesses of every size. Weak passwords, reused credentials, and exposed admin panels are avoidable risks, not sophisticated attacks.

    A properly managed IT environment closes most of these doors as standard. Routine patching, credential rotation, and enforced MFA would already block much of what this campaign relies on.

    How Infinity Cloud Can Help Secure Your Network
    This is exactly the kind of risk our managed IT services Melbourne clients rely on us to catch before it becomes a crisis. As part of our ongoing cyber security service, we review firewall and VPN configurations, enforce MFA across critical systems, manage patching schedules, and monitor for suspicious activity. You shouldn’t have to find out about an issue like this from the news.

    If you’re not sure whether your Fortinet devices, or any other part of your network, are exposed, now is a good time to check.

    Book a Free IT Health Check with Infinity Cloud →

    Source: Australian Cyber Security Centre