Crime Gang Sells Access to 74,000 Fortinet Firewall Devices
A criminal group is selling access to approximately 74,000 Fortinet firewall devices, utilizing what appear to be legitimate and recently acquired administrator credentials. This ongoing campaign involves large-scale credential harvesting against FortiGate SSL VPN appliances, with indications that the attackers are exploiting organizations that have not fully updated their password hashing mechanisms after firmware upgrades. Cybersecurity experts warn that the dataset includes credentials for major companies and government entities, urging organizations to rotate credentials, look for signs of compromise, and ideally avoid exposing FortiOS Management Interfaces directly to the internet while requiring multifactor authentication.
https://www.bankinfosecurity.com/crime-gang-sells-access-to-74000-fortinet-firewall-devices-a-32015