Leaked Fortinet Credentials Turn Edge Access Persistent

Fortinet exposure is no longer just about scanning the perimeter. NCSC says a threat actor leaked a credential database after brute-force, dictionary, and credential-stuffing attempts against internet-facing FortiGate and VPN portals, so reused passwords can still hand out access after the device itself is checked. The advisory follows global targeting of Fortinet firewalls and VPN gateways, with some potential impact in the UK. NCSC says organisations should investigate affected Fortinet edge devices, and it specifically calls out SSL VPN users because the login portal itself can become the entry point when the same username and password work elsewhere. That shifts the problem from one appliance to account-level perimeter compromise. A cleaned device does not help if stolen credentials still open VPN or admin access and let attackers back into the network.

Part of the PlainSec briefing for 2026-06-19

Sources