A global cyberattack campaign is quietly turning thousands of Fortinet firewalls into espionage tools — and Australian organisations are firmly in the crosshairs.
The Australian Cyber Security Centre (ACSC) has issued multiple critical alerts urging businesses to act immediately. The campaign, now dubbed FortiBleed, has already compromised more than 30,000 Fortinet devices across 200 countries — not through flashy zero-day exploits, but through something far more preventable: stolen passwords.
How FortiBleed Actually Works
The attackers — believed to be Russian-speaking threat actors — didn't need to find new vulnerabilities. They simply used credential dumps leaked from earlier Fortinet incidents in December 2025 and January 2026 to walk straight through the front door.
But here's what makes FortiBleed particularly dangerous: once a device is compromised, it doesn't just get hijacked — it gets weaponised. Compromised firewalls and VPN gateways are transformed into silent listening posts, quietly intercepting network traffic and harvesting fresh credentials from unsuspecting users. Those new credentials are then fed back into automated scanning tools to compromise even more devices.
It's a self-fuelling attack loop. Compromised devices harvest credentials, those credentials compromise more devices, which harvest more credentials. It's still running right now.
According to threat intelligence firm SOCRadar, this creates a compounding cycle that is difficult to break once it takes hold inside an organisation's network. The longer a compromised device sits undetected, the deeper the attackers' foothold becomes.
Why This Hits Differently
Most high-profile cyberattacks exploit newly discovered software vulnerabilities — the kind that require patches that don't exist yet. FortiBleed is different. Every device compromised in this campaign was unlocked with credentials that were already known to be exposed.
That makes this an avoidable incident for many organisations. The credentials used were leaked months ago. Businesses that rotated passwords, enforced multi-factor authentication, and upgraded their firmware were significantly harder to compromise. Those that didn't became targets.
For Melbourne businesses running Fortinet firewalls or VPN gateways — particularly those managing their own infrastructure rather than working with a managed IT provider — the question is not whether FortiBleed is a concern. The question is whether your device has already been added to the list.
Six Steps Fortinet and the ACSC Are Telling You to Take Right Now
Fortinet has released a situational analysis report alongside the ACSC alerts. Here is what every affected organisation should act on immediately:
-
1Terminate all active admin and VPN sessions Kill every current session right now. An attacker who is already inside will be using one of these. Don't give them time to establish persistence before you start cleaning up.
-
2Reset every credential — all of them Every admin account, every VPN user, every service account connected to the device. Use strong, unique passwords. If any of those passwords were in use before January 2026, consider them compromised.
-
3Enable multi-factor authentication everywhere MFA on all admin and VPN accounts is now a baseline requirement, not an optional extra. A stolen password alone should not be enough to get in.
-
4Upgrade your firmware to a supported version Fortinet versions 7.4, 7.6, or 8.0 support PBKDF2 password hashing, which is significantly more resistant to credential cracking. If you're running an older version, upgrading is not optional.
-
5Audit your logs for unauthorised access Look specifically for administrative logins from unexpected locations or times, configuration changes you didn't make, and new admin accounts that weren't created by your team.
-
6Lock down remote management access Restrict administrative access to trusted IP addresses only, or remove internet-facing management access entirely. There is no reason a firewall's admin interface needs to be reachable from the public internet.
Fortinet is actively contacting affected customers, but don't wait for that call. If you run Fortinet equipment and haven't rotated credentials since late 2025, act on these steps today.
The Bigger Picture for Australian Businesses
FortiBleed is a sharp reminder that a firewall is only as strong as the credentials protecting it. The most sophisticated perimeter security in the world offers no protection if the admin password is reused, weak, or sitting in a leaked database from six months ago.
This kind of attack — credential-based, quiet, and compounding — is precisely what proactive security monitoring is designed to catch early. Organisations with active monitoring in place and credential hygiene policies enforced were far less exposed than those relying on their firewall to silently do its job.
If your business runs Fortinet equipment and you're not certain about your current security posture, the BITS team can help you assess the situation, check for indicators of compromise, and put the right protections in place going forward.
Don't wait until something goes wrong to find out where the gaps are. Get in touch with the BITS team and we'll have an honest conversation about where things stand.