LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › 30K+ Fortinet Devices Compromised in Credential Heist

CRITICAL severityReportedHow we verify

30K+ Fortinet Devices Compromised in Credential Heist: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 13, 2026
30K+ Fortinet Devices Compromised in Credential Heist

Reported June 13, 2026.

CRITICAL
Severity
2
Data types exposed
June 13, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

More than 30,000 Fortinet devices were reported compromised in a credential heist disclosed on June 13, 2026. Users should check whether their devices or accounts were affected and take appropriate steps to secure access.

Severity & verification
CRITICAL severityReported
Account credentials exposed.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Researchers reported on June 13, 2026, that a credential harvesting campaign had compromised more than 30,000 Fortinet firewalls and VPN gateways located in 194 countries. The operation relied on credential stuffing and reuse of passwords obtained from earlier leaks against devices left reachable from the internet. Affected organizations span government, telecommunications, healthcare, education, finance, and critical infrastructure sectors. The number of individual people whose information may be involved remains unknown.

The incident underscores ongoing risks to network perimeter equipment when default or reused credentials are present and remote management interfaces are exposed. Because the devices control access to internal networks, their compromise can provide entry points for further activity even when the initial goal is simply credential collection.

Inside the incident

Public information states that the campaign targeted Fortinet devices through automated attempts using previously leaked username and password combinations. No specific start date for the activity, exact number of unique credentials obtained, or volume of data exfiltrated has been disclosed. The report indicates the operation is self-sustaining, meaning harvested credentials can be used to locate and compromise additional devices. Details on whether the attackers maintained persistent access after initial compromise or exfiltrated configuration files are not provided.

How a breach like this happens

Credential-stuffing campaigns typically begin with large lists of usernames and passwords collected from earlier website or service breaches. Automated tools then test those same combinations against internet-facing login portals, including VPN concentrators and firewall management interfaces. When organizations reuse passwords across personal and work accounts or leave remote access enabled without multi-factor authentication, a single reused credential can grant entry. Once access is obtained, attackers may harvest additional credentials stored on the device or use the foothold to scan for further targets. The process requires little manual intervention after the initial lists are assembled.

Who is 30K+ Fortinet Devices Compromised in Credential Heist?

The incident centers on Fortinet network security appliances deployed by organizations rather than on a single company. Fortinet manufactures firewalls and VPN gateways commonly used to protect network perimeters in both public and private sectors. These devices often sit at the boundary between internal networks and the internet, handling authentication for remote workers and enforcing access policies. When large numbers of such devices are affected across critical sectors, the aggregate exposure extends to the internal systems those organizations rely on for operations and data storage.

The information in question

The only data types explicitly named in available reporting are credentials and device access. No inventory of specific files, logs, or configuration details has been published. Organizations that operate Fortinet devices typically store user authentication records, network address information, and policy rules on those appliances. Whether additional internal data was accessed through the compromised devices is unconfirmed at this time.

Why it matters

Compromised perimeter devices can allow unauthorized observation or control of network traffic and remote connections. In sectors such as healthcare and critical infrastructure, this raises the possibility of service disruption or lateral movement to systems holding sensitive operational data. For individuals, the primary concern is the further circulation of credentials that may already have been reused elsewhere. Organizations face the operational task of locating every affected device, resetting credentials, and verifying that no additional access was retained.

If your data was in this claimed breach

Change passwords for any accounts that reuse credentials previously used on work-related systems, and enable multi-factor authentication wherever available. Review logs on Fortinet devices under your control for unexpected login attempts and restrict remote management access to trusted networks. You can run a free exposure scan of your email address against known breach data to check whether your credentials have appeared in past incidents that may have contributed to this campaign.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

CISA Adds Three Vulnerabilities to Known Exploited Vulnerabilities CatalogAugust 11, 2026Brazilian IT Firm Service IT Breached by WorldLeaksJuly 3, 2026Nissan Discloses Employee Data Breach via Oracle PeopleSoft Zero-DayJune 25, 2026Icarus Group Steals Salesforce Data via Klue OAuth BreachJune 18, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the 30K+ Fortinet Devices Compromised in Credential Heist →

Source: Dark Reading

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram