Major hack campaign against Fortinet devices
Researchers at Hudson Rock said a major hacking campaign targeting Fortinet firewall and VPN devices has compromised systems in at least 15 countries, with evidence of password theft at Fortune 500 firms and government agencies. Hudson Rock estimated about 75,000 devices affected, mostly in the US, India and Taiwan. Fortinet said it is aware of credential-stealing attempts using data from prior incidents and repeated password guessing, and denied links to recent advisories.

Credential theft and potential intrusions raise near-term risk around Fortinet’s installed base, incident response, and customer trust.
Fortinet said it is aware of a campaign stealing login credentials from its firewall and VPN devices, with ~75,000 units potentially compromised.
Bias to downside/volatility for FTNT on incident escalation, customer disclosures, or regulatory scrutiny; magnitude uncertain without confirmed breach counts.
Background
Researchers (Hudson Rock) allege a sweeping campaign targeting Fortinet firewall/VPN devices, with evidence of password theft and potential deeper penetration.
Why it matters
If credential theft leads to confirmed breaches, it can pressure Fortinet’s reputation, trigger customer remediation costs, and invite regulatory/contractual scrutiny; if scope is overstated, the impact may fade quickly.
Market relevance
A large-scale credential-theft claim tied to Fortinet devices is a near-term risk catalyst for FTNT and the broader network security complex.
Market effects
Highlights heightened cyber risk for network security vendors’ installed bases and may increase scrutiny of VPN/firewall credential hygiene across enterprises.
Most affected devices cited in the US, India, and Taiwan, potentially driving localized incident-response and procurement reviews.
Cross-border compromise evidence (15+ countries) can broaden concern for global enterprise remote-access security.
Alternative perspectives
Fortinet frames activity as using data from previous incidents and does not link it to a recent advisory; confirmed customer intrusions may be lower than the device-compromise count.
Market reaction may depend on whether Fortinet releases mitigation guidance, whether regulators open inquiries, and whether affected customers disclose material impacts.
Key entities
- companyFortinet
Security vendor whose firewall and VPN devices are alleged to be compromised and whose statement acknowledges credential-theft activity.
- research_firmHudson Rock
Cybercrime-tracking firm estimating ~75,000 Fortinet devices compromised and describing the campaign’s scale.
- government_agencyCISA
US cyber defense agency referenced as not immediately responding to Reuters.
- government_agencyFBI
US federal agency referenced as not immediately responding to Reuters.

