:

RUSSIAN HACKERS BREACH TENS OF THOUSANDS OF FORTINET FIREWALLS

SECURITY DESK2 MIN READ
WED, JUN 17, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A Russian-speaking cybercriminal group is actively compromising Fortinet firewalls and VPNs used by major companies worldwide, exploiting previously known passwords to gain access to corporate networks.

Security researchers have identified a coordinated campaign targeting Fortinet FortiGate firewalls and VPN systems across multiple industries and geographic regions. The attackers are leveraging credentials that were previously disclosed or obtained through prior breaches, rather than exploiting zero-day vulnerabilities. The scale of the compromise affects tens of thousands of devices belonging to enterprises, government agencies, and critical infrastructure operators. Fortinet firewalls are widely deployed as primary security perimeters for organizations of all sizes, making them high-value targets for attackers seeking network access. The Russian-speaking threat actors reportedly gained initial access through reused or weak credentials. Once inside, they can pivot to lateral movement within compromised networks, potentially accessing sensitive data and systems. Security experts warn that organizations using Fortinet equipment may already be affected without detection. Fortinet has not yet issued an official public statement regarding the scope of the breach. However, the company has previously advised customers to change default passwords and implement multi-factor authentication on all network appliances. Recommended Actions: Organizations should immediately audit their Fortinet firewall credentials and reset any default or weak passwords. Companies should review firewall logs for suspicious login attempts and unauthorized access. Enabling multi-factor authentication on all remote access points is critical. Additionally, implementing network segmentation and monitoring for unusual lateral movement can help detect compromised systems. Security teams should treat this as a potential active threat until their specific deployments can be verified as secure. Given the scale of the campaign and the widespread use of Fortinet equipment, many organizations are likely already targeted.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A security researcher has developed an algorithm that generates computer-generated patterns capable of evading detection by surveillance cameras. The technique can hide people, faces, and vehicles from AI-powered monitoring systems.

1H AGOSecurity Desk

Scammers are enrolling fake students at US community colleges, using artificial intelligence to complete coursework, and collecting financial aid payouts. The scheme exploits gaps in enrollment verification and assignment monitoring.

2H AGOAI Desk

The Head Mare hacktivist group has compromised TrueConf video conferencing servers and replaced legitimate client installers with trojaned versions containing backdoors.

7H AGOSecurity Desk

OpenAI inadvertently launched a denial-of-service attack against Hugging Face, the popular machine learning platform. The incident has prompted questions about AI infrastructure security and unintended consequences of large-scale operations.

YESTERDAYAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.