The UK’s National Cyber Security Centre issued an urgent alert this week after a major credential leak — now being called FortiBleed — exposed administrator usernames, passwords and configuration data for more than 73,000 Fortinet FortiGate firewalls and VPN gateways worldwide. Researchers estimate that around half of all internet-reachable FortiGate devices are affected, and the stolen database is now circulating in criminal underground forums.

Fortinet kit is widely used by UK small businesses precisely because it offers enterprise-level performance at an SME-friendly price. If your office firewall or remote-access VPN is a Fortinet product — FortiGate, FortiClient, FortiWifi — your business may be in the dataset.

What actually happened

The exposure resulted from a sustained credential-stuffing campaign: automated tools hammered internet-facing FortiGate devices with dictionary attacks, collecting valid admin logins at scale. Once assembled into a structured database, the data was traded and then leaked publicly in mid-June 2026.

The NCSC’s critical warning: simply changing your password may not be enough. If attackers have already used those credentials to establish persistence — planting a backdoor account, modifying firewall rules, or installing a rogue certificate — resetting the password leaves the back door intact. The NCSC recommends a full factory reset followed by a rebuild from a known-clean configuration.

That sounds daunting for an SME without a dedicated security team. But there are clear, prioritised steps you can take this week.

What to do right now

Start by checking whether your Fortinet device has SSL VPN enabled or exposes a management interface to the internet. Most SME FortiGate units are configured this way out of the box for remote access.

Check the NCSC lookup guidance first. The NCSC has issued advisory tooling to help organisations verify whether their device IPs appear in the leaked dataset. Do this before anything else.

Enable MFA on all admin and VPN logins. Multi-factor authentication stops credential-only attacks immediately. Even if you’re not in the FortiBleed dataset, this is non-negotiable for any internet-facing device.

Update firmware. Ensure your FortiGate is running the latest firmware release. Exploit activity typically follows credential leaks quickly as attackers hunt for secondary vulnerabilities on devices they know are weakly managed.

Factory reset if in doubt. If your device IP appears in the dataset, or if you cannot verify your configuration history, a clean rebuild is the safest path. A competent IT provider can do this without extended downtime.

If you use a managed service for your firewall, call them today and ask specifically whether they have assessed your FortiGate against the FortiBleed advisory. A reputable provider will already be acting on this proactively.

Why SME perimeter devices are prime targets

FortiBleed is the latest reminder that firewalls and VPN gateways are actively hunted by threat actors. They sit at the edge of your network — compromise one and an attacker gains a foothold that is very hard to detect without active monitoring in place.

Services like KeepSafe continuously monitor for exactly this kind of exposure, checking whether your business IP addresses or credentials have appeared in known breach datasets and alerting you before attackers exploit the access. For businesses without a full security operations team, that early warning is often the difference between a contained incident and a ransomware event.

The NCSC rates the risk as significant. With the FortiBleed database now in public circulation, the gap between “credentials leaked” and “credentials used” is narrowing by the day.

The action this week

Check the NCSC advisory, enable MFA on all Fortinet logins if it is not already on, and ask your IT provider for a firmware audit. This is not a watch-and-wait situation — it is an act-this-week situation.