Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.

Fortinet firewalls and VPN gateways have been targeted as part of a global campaign, with some indications of potential impact in the UK.
A database of credentials has been leaked by a threat actor following brute-force, dictionary and credential stuffing attempts against internet-facing FortiGate and VPN portals.
Credential stuffing is a method where attackers use passwords stolen from one web service to try to access accounts on other services, taking advantage of any reuse of username and password combinations.
Organisations using these products should prioritise investigating whether they have been affected and, as soon as possible, follow mitigation advice to help defend against the threat.
Use one of the FortiBleed asset checkers for any domains that may have been affected:
UK organisations using Fortinet edge devices with SSL VPN enabled should investigate potentially malicious activity on the device and monitor their network for unusual activity.
Fortinet has published a blog post providing guidance and an analysis.
The priority actions should be:
The NCSC's Early Warning service provides UK organisations with alerts for malicious activity affecting their networks. This free service offers potentially invaluable time to detect and stop a cyber incident.
Learn more about Early Warning.


