
Massive Theft of Business Security Credentials Affects Companies in 200 Countries
Hackers have stolen working login credentials for over 30,000 business security devices worldwide, putting company networks and employee information at risk.
Source
Dark Reading
Original headline: Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices
Plain-English summary by GetCyberRight. Read the full report at the source above.
Cybercriminals have successfully compiled a list of working usernames and passwords for more than 30,000 Fortinet security devices that protect business networks across nearly 200 countries. These devices act as digital gatekeepers for companies, controlling who can access internal systems, employee records, and sensitive business information. The attackers are actively targeting organizations in various industries, and they now have verified credentials that actually work to break into these protected systems.
This breach affects employees at companies and organizations that use Fortinet devices for network security. If you work for a company that allows remote access or has employees who work from home, your employer likely uses security devices like these.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
When hackers gain access to these systems, they can potentially view employee personal information, payroll records, health insurance details, and customer data. Your home address, Social Security number, bank account information for direct deposit, and other sensitive employment records could be at risk. Take action right now to protect yourself:
- Contact your employer's IT or human resources department immediately to ask if your company uses Fortinet security systems and whether they have been compromised.
- Change your work-related passwords, especially for VPN access, email, and any systems you use to access company resources remotely.
- Monitor your bank accounts and credit reports closely for any unusual activity, since hackers with access to company systems may have viewed your direct deposit and tax information.
- Be extremely cautious about any emails claiming to be from your IT department asking for passwords or personal information, as attackers often use stolen access to launch follow-up scams against employees. Protect yourself long-term by treating your work accounts with the same security mindset you use for banking. Never share work passwords with anyone, including family members. Use different passwords for work and personal accounts. If your company offers security training, take it seriously. Ask your employer what steps they are taking to protect employee data and what you should do if you suspect a breach. Consider freezing your credit if you work for an organization that may have been affected, as this prevents criminals from opening new accounts in your name even if they have your personal information.
Curated from trusted cybersecurity sources by GetCyberRight
Source: Dark ReadingStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Hackers Are Using Your IT Department's Tools Against You
Attackers are installing legitimate remote access software to maintain secret access to business computers. Here's how to spot the warning signs.
3 min readYour Phone Is Broadcasting Your Location: Here's How to Stop It
Smartphones track your family's location through multiple hidden methods. Learn which apps are watching you and how to take back control right now.
3 min readHospital Worker Accessed Royal Medical Records: What Families Should Know
A hospital employee faces prosecution for viewing the Princess of Wales's private medical records. This insider threat exposes privacy risks in every healthcare system.
3 min readMFA Isn't Enough Anymore: What Families Need to Know About Modern Attacks
Attackers have learned to bypass multi-factor authentication. A new webinar explains how these tactics work and what actually protects your accounts now.
3 min read