Back to all lessons
Awareness Lessons
4 months ago

Russian IAB Exploits Unpatched FortiGate Devices to Harvest 110M+ Credentials

A Russian initial access broker has been systematically exploiting unpatched FortiGate firewalls since at least February, leveraging custom tools to sniff and crack over 110 million credentials from more than 430,000 devices. The root cause is a failure to apply critical patches to internet-facing network appliances in a timely manner, leaving a massive attack surface exposed to well-resourced adversaries. The scale of credential harvesting means entire identity infrastructures — including VPN accounts, authentication tokens, and privileged access credentials — may be compromised across victim organizations. The confirmed breach of a NATO-aligned defense contractor underscores that the consequences extend beyond individual organizations into national security and supply chain integrity.

Tactical Insight

Immediate actions

  • Apply all available FortiGate firmware patches immediately and verify patch status across every internet-facing appliance in your inventory.
  • Force a full credential reset for all accounts that authenticate through FortiGate VPNs or any potentially affected network devices.
  • Isolate any FortiGate devices that cannot be immediately patched by placing them behind additional network controls or taking them offline.

Detection measures

  • Deploy network traffic monitoring to detect anomalous credential harvesting or lateral movement patterns originating from perimeter devices.
  • Review firewall and VPN logs for signs of FortigateSniffer-style packet capture activity or unusual authentication bursts.
  • Enroll all FortiGate management interfaces in continuous vulnerability scanning tied to real-time CVE feeds.

Long-term improvements

  • Implement a formal patch SLA policy requiring critical patches on internet-facing infrastructure to be applied within 24–72 hours of release.
  • Enforce multi-factor authentication (MFA) on all VPN and remote access entry points to limit the impact of harvested credentials.
  • Maintain a continuously updated asset inventory of all network appliances and segment critical systems to limit lateral movement in the event of a perimeter breach.