FortiBleed fallout: how to check whether firewall and VPN credentials are exposed

If your business uses a Fortinet FortiGate firewall or Fortinet SSL VPN, treat admin and VPN credentials as potentially exposed and act quickly. FortiBleed is not a single new software bug with one simple patch. It is a large credential exposure affecting internet-facing Fortinet devices, with leaked usernames and passwords linked to brute-force, dictionary and credential-stuffing activity.

The US Cybersecurity and Infrastructure Security Agency urged organisations to harden Fortinet devices after reports of exposed credentials associated with about 74,000 devices. The UK’s National Cyber Security Centre also warned that Fortinet firewalls and VPN gateways had been targeted globally, with indications of possible UK impact.

The response is straightforward: reset passwords, enable multi-factor authentication, remove public access to management interfaces, update FortiOS, and check logs for activity you cannot explain.

Why FortiBleed is different

The usual instinct after a security alert is to patch and move on. That is not enough here. FortiBleed is about credentials that may already have been harvested, tested, shared or sold. Even if your firewall is fully patched today, an old or reused password could still be circulating.

The leaked data reportedly includes credentials gathered from earlier Fortinet-related incidents and more recent attacks against exposed portals. That means a business that “fixed” an older vulnerability but never rotated credentials or enabled MFA may still be at risk.

Password resets are necessary, but they are not the end of the job. If an attacker used valid credentials before you changed them, they may have altered configuration, added accounts, changed VPN settings, or found another way into the network. That is why log review and configuration checks matter as much as the reset itself.

How to check and respond

ActionWhy it mattersWhen
Reset all FortiGate admin and VPN passwordsLeaked credentials are the direct route inNow
End active sessionsStops existing authenticated sessions from continuingNow
Enable MFA for all admin and VPN usersPrevents a stolen password working on its ownNow
Remove public access to admin interfacesReduces brute-force and credential-stuffing exposureNow
Review login and configuration logsFinds suspicious access a password reset will not undoThis week
Update FortiOS and confirm support statusCloses known related vulnerabilitiesThis week
Check exposed credentialsShows whether company logins are already circulatingThis week

Start with the device itself. Reset every local admin, SSL VPN and privileged account connected to any internet-facing FortiGate. Disable unused accounts, end active sessions and enforce MFA. Then restrict management access so it is only reachable from trusted IP addresses, a VPN management network or a secure administrative route.

Next, check for forgotten exposure. Regular vulnerability management and routine vulnerability scanning help identify devices, portals and old appliances that should not be reachable from the public internet.

Check whether credentials are already out there

To understand whether your domain, staff emails or VPN credentials have appeared in breach data, use dark web monitoring. It scans criminal forums, leak sites and breach dumps for company information so you can reset credentials before they are used.

This matters because leaked logins often feed the next phishing or account takeover attempt. A stolen password for a VPN account may be tried against email, cloud systems, remote desktop, supplier portals or finance platforms.

Once the immediate changes are made, watch for misuse. A managed SOC service can flag unusual VPN logins, impossible travel, out-of-hours access and suspicious firewall events. MDR services add people who can investigate and contain a threat if something looks wrong. A quick penetration test can also confirm whether your perimeter and VPN changes hold up.

Do not forget your users

Credential theft is still one of the easiest ways into a business. The UK government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses identified a breach or attack in the previous 12 months, with phishing remaining the most common type of attack.

Technical controls need staff support. MFA, strong passwords and update prompts only work if people understand why they matter. Short, regular cyber security awareness training helps turn those rules into everyday habits.

FortiBleed is a reminder that perimeter devices are prime targets and credentials are the currency. If you would like help checking your exposure and locking down firewall and VPN access, Northern Star’s managed IT support services in London can run the checks with you. Call the team on 0800 319 6032 to get started.

Focus on Complete Cloud Enablement and Cybersecurity

Building a resilient digital environment requires a smart combination of cloud innovation and proactive defense. At Northern Star, we elevate your workflow with robust Microsoft 365 support in London and flexible Microsoft Azure management in London. We also guide your AI adoption with expert Microsoft Copilot advisory services, protect communications with London email security, and upskill your employees using essential cybersecurity awareness training.

We defend your infrastructure round-the-clock using our comprehensive managed SOC and swift MDR solutions in London. Our specialists proactively handle threats through vulnerability assessment in London to seal security gaps. If a disruption happens, our cyber incident management and disaster recovery and business continuity ensure you never lose operational momentum. Let us support you.