Two weeks ago, the NCSC warned that a leaked database of Fortinet firewall credentials — dubbed FortiBleed — put more than 70,000 devices worldwide at risk. This week, that warning stopped being theoretical. Reports on 5 July revealed that Russian-linked hackers had used the leaked credentials to breach email accounts belonging to UK Foreign Office staff, embassy personnel, and local government officials, in an attack researchers are still calling FortiBleed. Credentials tied to the NHS, energy providers and pharmaceutical suppliers were also found in the exposed dataset, and the stolen logins are now being traded on dark web forums for up to $60,000 apiece.
If your business runs a Fortinet FortiGate firewall or VPN and you filed the earlier NCSC alert away as “important but not urgent,” this is the moment that assumption needs revisiting.
From warning to breach — what actually changed
The original leak was a credential-stuffing haul: usernames, passwords and configuration data harvested from internet-facing FortiGate devices and compiled into a database. At the time, it was a supply of stolen keys with no confirmed break-ins attached to it. What’s changed is that attackers have now demonstrably used that supply — reaching not just isolated small businesses but UK government systems and critical national infrastructure suppliers. That matters for SMEs because it proves the exploitation pipeline works end to end: leaked credentials are being actively weaponised, not just hoarded. The gap between “your details might be in a leaked database” and “someone is using them” has closed.
It’s also a reminder that being a small business is no protection here. NHS and energy-sector credentials weren’t targeted because those organisations are famous — they were targeted because they were in the dataset. If your Fortinet device’s admin credentials were in that same leak, the attackers scanning for usable access don’t care how big your company is.
What to check today, not this month
If you haven’t already, find out whether your Fortinet device is affected. The NCSC’s advisory tooling lets you check whether your device IPs appear in the leaked dataset — do that first. If you’re in the dataset, or you can’t be certain of your configuration history, a password reset is not enough. The NCSC’s guidance remains that attackers who’ve already established persistence — a hidden admin account, an altered firewall rule — will survive a simple credential change. A full factory reset and rebuild from a clean configuration is the only reliable fix.
Beyond that specific check, this is also a good prompt to confirm MFA is enabled on every admin and VPN login on your network, and that firmware is current. If you outsource your firewall management, call your provider today and ask directly whether they’ve assessed your setup against FortiBleed specifically — not cybersecurity generally.
Why ongoing monitoring matters more after news like this
The unsettling part of this story isn’t the initial leak — it’s that the escalation from “credentials exposed” to “government systems breached” happened quietly, over roughly three weeks, before most affected organisations would have known to look. Services like KeepSafe exist to close that visibility gap for smaller organisations, continuously checking whether your business’s credentials or IP addresses have surfaced in breach datasets so you find out from your own monitoring rather than from a news report weeks later.
The takeaway
FortiBleed has moved from advisory to active exploitation, reaching UK government and NHS-linked credentials. If you run Fortinet kit and haven’t checked the NCSC’s lookup tool yet, do it today — and if your device is affected, don’t stop at a password reset. This is exactly the kind of gap between disclosure and exploitation that’s shrinking across the board, and firewalls sitting on the edge of your network are the first place attackers look.