Thursday, 1 October 2026

Where technology leaders come to think out loud

ColumnCybersecurity

FortiBleed shows the VPN password is still the weakest door

The NCSC has told FortiGate users to check whether their VPN credentials were leaked in a global campaign. But the real fix is one more than half of UK businesses have yet to make: two-factor login

Illustration of a laptop and tablet with red alert symbols
Image: NCSC (OGL)
In brief
  • Fortinet says FortiBleed is not a new vulnerability but reused and brute-forced credentials against devices without MFA.
  • In the official 2025/2026 breaches survey, 90% of large businesses required two-factor login against 43% of micro businesses, many of which rely on outside security providers.
  • Smaller firms that outsource their firewall should ask their provider for written answers on MFA, admin passwords and exposed management interfaces.

On 18 June the National Cyber Security Centre (NCSC) issued an alert urging organizations that use Fortinet firewalls and VPN gateways to act. It said a threat actor had leaked a database of credentials after brute-force, dictionary and credential stuffing attempts against internet-facing FortiGate and VPN portals, in a global campaign with “some indications of potential impact in the UK”. A third-party security firm has labeled the campaign ‘FortiBleed’.

Fortinet’s answer came on its product security incident response team (PSIRT) blog on 19 June: “This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory.” Its initial analysis is that attackers reused credentials from earlier incidents and used brute force against devices “with weak password hygiene and no multi-factor authentication (MFA)”. The company said it was contacting customers whose systems may have been compromised.

That is the vendor’s account, and its investigation is still under way. But the NCSC’s own mitigation list points the same way: enforce MFA on all VPN and device management logins, change default, generic or reused administrator passwords and keep management interfaces off the internet.

For small and mid-sized UK firms, the lesson is uncomfortable. FortiBleed is less a story about one vendor’s firewall than about the password that still guards the front door of a great many businesses, and about who holds the key.

The limits of patching

The familiar edge-device alert is about patching: a flaw, a fix and a race to apply it. On Fortinet’s account, this one is different. If the route in was reused and guessed passwords, then keeping firmware current would not on its own have protected a VPN that accepted a password with nothing else behind it.

That matters most for organizations that judge their edge security by whether the last update went on. The NCSC also warned that changing credentials alone may not be enough if attackers have gained persistence on a device. Where there is evidence of compromise, it advised isolating the device from the internet and the internal network and then resetting it to factory settings, after saving the logs and configuration needed for an investigation.

For a firm with one firewall and no spare, that is real disruption. It is also avoidable, which is the point.

The numbers behind the door

Official data suggests the gap is not a niche one. The government’s Cyber Security Breaches Survey 2025/2026, published on 30 April and based on a survey of 2,112 UK businesses between August and December 2025, found that 47% of businesses had any requirement for two-factor authentication, up from 40% a year earlier. Among large businesses the figure was 90%. Among micro businesses it was 43%.

The same survey shows how much smaller firms rely on outside help. External cybersecurity or IT consultants and providers were the most common source of security advice, used by 51% of medium-sized businesses and 39% of small ones. The proportion of micro businesses with an external cybersecurity provider rose to 44%.

That reliance is sensible. Few small firms can or should run a firewall themselves. But it can mean that at many businesses the VPN password policy is something the board has never seen, set by a supplier it pays, and tested only when something goes wrong.

Questions for the next supplier review

The NCSC alert gives security leaders, and the directors of firms that have no security leader, a checklist they can turn into questions for whoever runs their edge devices:

  • Is MFA enforced on every VPN and device administration login?
  • Are any administrator passwords default, generic or reused across devices?
  • Can the device’s management interface be reached from the internet?
  • Is the device on a current, supported software version?
  • Has anyone checked whether the organization has been affected, as the NCSC asks every Fortinet user to do?

None of these questions needs a new product or a bigger budget. Each needs someone inside the business to ask it and to expect a written answer. For a firm whose firewall and VPN are run by a managed service provider, that answer belongs in the contract and the quarterly review, not in an email sent after an alert.

Fortinet’s guidance adds further steps, including upgrading to versions that support PBKDF2 hashing of administrator credentials and reviewing devices for unrecognized accounts. Those are the provider’s job. Knowing whether they have been done is the customer’s.

Whatever the final account of FortiBleed, the method described so far needed no new vulnerability. A password that works on its own is no longer a control. It is an invitation.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. National Cyber Security Centre, “Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways”, 18 June 2026. https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways
  2. Fortinet, “Analysis of Reported Credential Compromise of FortiGate Devices”, PSIRT blog, 19 June 2026. https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices
  3. Department for Science, Innovation and Technology, “Cyber security breaches survey 2025/2026”, official statistics, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →