Scoopfeeds — Intelligent news, curated.
computer-science

Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world

TechCrunch · Jun 17, 2026, 6:20 PM

Key takeaways

  • Cybercriminals have compromised tens of thousands of Fortinet firewalls and VPNs used by major companies all over the world, according to two cybersecurity firms.
  • In this campaign, hackers are first using automated tools to scan the internet for exposed Fortinet firewalls and VPNs.
  • “Once a device is compromised, [the hackers] use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by.

Cybercriminals have compromised tens of thousands of Fortinet firewalls and VPNs used by major companies all over the world, according to two cybersecurity firms.

The widespread hacking campaign, which is ongoing and has been dubbed Forti Bleed, appears to not involve abusing any unknown vulnerability in the targeted devices, but rather on a more basic issue: companies may not be changing passwords to the firewall, nor making sure that the credentials they use for sensitive systems exposed on the internet are not already known by hackers.

In this campaign, hackers are first using automated tools to scan the internet for exposed Fortinet firewalls and VPNs. Then, they are breaking into the devices thanks to lists of previously known passwords. At that point, the cybercriminals can steal more sensitive data from the victim companies, cybersecurity firms Hudson Rock and SOCRadar wrote in their reports that they published this week.

Article preview — originally published by TechCrunch. Full story at the source.
Read full story on TechCrunch → More top stories
Aggregated and edited by the Scoop newsroom. We surface news from TechCrunch alongside other reporting so you can compare coverage in one place. Editorial policy · Corrections · About Scoop