Fortinet VPN sustained credential attack campaign
Campaign
Updated: 15.09.2026 09:11
· First: 15.09.2026 09:11
· 📰 1 src / 1 articles
· H score: 38
A Fortinet VPN credential attack campaign hit multiple U.S. customer environments in two sustained waves, generating tens of millions of authentication failures. The targeting used organization-specific usernames and other identity data rather than generic spraying, pointing to previously collected or enumerated credentials. One observed successful authentication was followed by malicious activity, increasing the risk of unauthorized access in affected environments.