
Major Security Leak Exposes Business VPN Passwords: Why This Matters for Remote Workers
A data leak has exposed VPN login credentials for 73,932 Fortinet firewall devices used by businesses worldwide. If your workplace uses this system, your access may be compromised.
Source
BleepingComputer
Original headline: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
Plain-English summary by GetCyberRight. Read the full report at the source above.
A newly discovered data leak called FortiBleed has exposed login credentials for 73,932 Fortinet and FortiGate VPN devices used by organizations around the world. VPN stands for Virtual Private Network, which is what many employees use to securely connect to their workplace computers from home. This leak means that hackers could potentially access the internal networks of thousands of businesses. This directly affects you if you work remotely and your employer uses Fortinet or FortiGate VPN systems to let you access work files from home. With these stolen credentials, hackers could log in as if they were legitimate employees and access company data, customer information, or financial records.
Even if you are not a remote worker, this could affect you if you are a customer of a business whose systems get breached through these compromised VPNs.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
If you use a VPN to connect to work, take these steps immediately:
- Contact your IT department right away and ask if your company uses Fortinet or FortiGate VPN systems.
- Change your work VPN password immediately, even if your company has not told you to.
- If your company offers two-factor authentication for VPN access, make sure it is turned on.
- Watch for suspicious activity on work accounts and report anything unusual to your IT team. Going forward, always use unique passwords for work systems that are different from your personal account passwords. If hackers gain access to your work VPN, you do not want them to also have the password you use for your bank or email. Ask your employer about their security practices for remote access. Companies should be using two-factor authentication for all VPN connections and monitoring for suspicious login attempts from unusual locations.
Curated from trusted cybersecurity sources by GetCyberRight
Source: BleepingComputerStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Major Security Leak Exposes Business Network Passwords Worldwide
A data leak called FortiBleed exposed login credentials for nearly 74,000 business firewalls that protect company networks and remote workers.
2 min readIrish Hospital Fined After Patient Records Were Exposed in Cyberattack
A ransomware attack on an Irish hospital exposed patient data in 2018. The hospital's health service has been fined €300,000 for failing to protect records properly.
2 min readIrish Hospital Fined After Patient Records Breach: What Medical Data Leaks Mean for You
A ransomware attack on an Irish hospital exposed patient data in 2018. The hospital's health system has now been fined €300,000 for failing to protect records.
2 min read
Why Hackers Can Break Into Systems Faster Than Ever Before
Cybercriminals are getting faster at breaking into websites and online services. Understanding how they work helps you protect your family's information.
2 min read