Stolen FortiGate access is locking out admins and feeding ransomware
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, October 8th, 2026.
Organizations are losing administrative control of exposed FortiGate firewalls and V P N gateways during an ongoing credential-based campaign. Attackers are using leaked or stolen logins, cracking harvested password hashes, and creating new administrator accounts. In some cases, they delete existing accounts or change their passwords, locking legitimate teams out. More than eighty six thousand devices across 194 countries were estimated to be compromised, and the access has been linked to ransomware affiliates.
For leaders, this can turn an overlooked identity weakness at the network edge into operational disruption and a ransomware incident. For defenders, patching alone is insufficient because the campaign relies heavily on valid credentials and persistent accounts. An affected organization may need to recover control of the appliance while checking whether the attacker moved further into the network. The broader lesson is that identities on edge devices need the same protection and monitoring as other privileged enterprise accounts.
Prioritize restricting external access, terminating active sessions, resetting credentials, enforcing phishing-resistant authentication, and investigating unauthorized changes.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.