---
title: "NCSC warns UK organisations over global Fortine… | Firevault"
description: "The National Cyber Security Centre has issued an alert after a threat actor leaked a database of credentials harvested from brute-force and…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak#webpage",
      "url": "https://fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak",
      "name": "NCSC warns UK organisations over global Fortine…",
      "description": "The National Cyber Security Centre has issued an alert after a threat actor leaked a database of credentials harvested from brute-force and…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/b4a021e4-2b1e-493e-9363-128798186f7b/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "NCSC warns UK organisations over global Fortinet firewall and VPN credential leak",
          "item": "https://fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "NCSC warns UK organisations over global Fortinet firewall and VPN credential leak",
      "description": "The National Cyber Security Centre has issued an alert after a threat actor leaked a database of credentials harvested from brute-force and credential-stuffing attacks against internet-facing Fortinet firewalls and VPN gateways. UK organisations using FortiGate or Fortinet VPN portals are urged to investigate exposure and apply mitigations immediately.",
      "url": "https://fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/b4a021e4-2b1e-493e-9363-128798186f7b/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/b4a021e4-2b1e-493e-9363-128798186f7b/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/b4a021e4-2b1e-493e-9363-128798186f7b/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/b4a021e4-2b1e-493e-9363-128798186f7b/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-08T17:15:23.865935+00:00",
      "dateModified": "2026-08-11T21:29:24.285561+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 514,
      "keywords": "NCSC, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "The National Cyber Security Centre (NCSC) has issued an alert to organisations using Fortinet firewalls and VPN gateways, following a global campaign that has produced a leaked database of credentials for internet-facing FortiGate and Fortinet VPN portals. The NCSC has indicated potential impact in the UK and is urging affected organisations to act without delay. What has happened A threat actor h",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What has happenedWho is affectedWhy this mattersNCSC recommended actionsThe offline alternativeKey takeawaysShareMore Resources

[Knowledge Vault](/learn/knowledge)/ Breach Analysis 

Breach Analysis · 8 July 2026 

# NCSC warns UK organisations over global Fortinet firewall and VPN credential leak

The National Cyber Security Centre has issued an alert after a threat actor leaked a database of credentials harvested from brute-force and credential-stuffing attacks against internet-facing Fortinet firewalls and VPN gateways. UK organisations using FortiGate or Fortinet VPN portals are urged to investigate exposure and apply mitigations immediately.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak&text=NCSC%20warns%20UK%20organisations%20over%20global%20Fortinet%20firewall%20and%20VPN%20credential%20leak%0A%0AThe%20National%20Cyber%20Security%20Centre%20has%20issued%20an%20alert%20after%20a%20threat%20actor%20leaked%20a%20database%20of%20credentials%20harvested%20from%20brute-force%20and%20credential-stuffing%20attacks%20against%20internet-facing%20Fortinet%20firewalls%20and%20VPN%20gateways.%20UK%20organisations%20using%20FortiGate%20or%20Fortinet%20VPN%20portals%20are%20urged%20to%20investigate%20exposure%20and%20apply%20mitigations%20immediately.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak)[](mailto:?subject=NCSC%20warns%20UK%20organisations%20over%20global%20Fortinet%20firewall%20and%20VPN%20credential%20leak&body=The%20National%20Cyber%20Security%20Centre%20has%20issued%20an%20alert%20after%20a%20threat%20actor%20leaked%20a%20database%20of%20credentials%20harvested%20from%20brute-force%20and%20credential-stuffing%20attacks%20against%20internet-facing%20Fortinet%20firewalls%20and%20VPN%20gateways.%20UK%20organisations%20using%20FortiGate%20or%20Fortinet%20VPN%20portals%20are%20urged%20to%20investigate%20exposure%20and%20apply%20mitigations%20immediately.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak)

![Row of rack-mounted network firewall appliances in a dim data centre corridor lit with cool blue and magenta accent lighting](/__l5e/assets-v1/b4a021e4-2b1e-493e-9363-128798186f7b/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak-2x.jpg)

Breach Analysis 

Article record

**Breach Analysis**Category 

**8 July 2026**Published 

**3 min read**Reading time 

**Mark Fermor**Written by 

Row of rack-mounted network firewall appliances in a dim data centre corridor lit with cool blue and magenta accent lighting

Why it matters

## What this means for organisations holding critical data

The National Cyber Security Centre has issued an alert after a threat actor leaked a database of credentials harvested from brute-force and credential-stuffing attacks against internet-facing Fortinet firewalls and VPN gateways. UK organisations using FortiGate or Fortinet VPN portals are urged to investigate exposure and apply mitigations immediately.

In this analysis

1.  01 [What has happened](#section-0)
2.  02 [Who is affected](#section-1)
3.  03 [Why this matters](#section-2)
4.  04 [NCSC recommended actions](#section-3)
5.  05 [The offline alternative](#section-4)
6.  06 [Key takeaways](#section-5)

**On this page**[What has happened](#section-0)[Who is affected](#section-1)[Why this matters](#section-2)[NCSC recommended actions](#section-3)[The offline alternative](#section-4)[Key takeaways](#section-5)

The **National Cyber Security Centre (NCSC)** has issued an alert to organisations using Fortinet firewalls and VPN gateways, following a global campaign that has produced a leaked database of credentials for internet-facing FortiGate and Fortinet VPN portals. The NCSC has indicated potential impact in the UK and is urging affected organisations to act without delay.

## What has happened

A threat actor has published a database of credentials gathered through **brute-force, dictionary and credential-stuffing attempts** against internet-facing FortiGate devices and Fortinet VPN portals. Credential stuffing relies on username and password combinations stolen from unrelated services being reused on other systems, so any organisation whose staff or administrators reuse passwords is at heightened risk.

## Who is affected

The NCSC advises that any organisation exposing Fortinet firewall management or VPN services to the internet should assume it may be in scope. Organisations should use one of the **FortiBleed asset checkers** referenced by the NCSC to test any domains that could have been targeted, and should treat a positive result as a compromise until proven otherwise.

## Why this matters

Firewalls and VPN gateways sit at the perimeter of the network. A working credential for one of these devices gives an attacker a foothold that bypasses most internal controls, opening the door to lateral movement, data theft, deployment of ransomware and quiet persistence via new administrator accounts or VPN tunnels. Because these devices are trusted by design, malicious activity through a valid login is often difficult to distinguish from legitimate remote access.

## NCSC recommended actions

-   **Patch immediately.** Apply the latest Fortinet firmware for FortiOS, FortiGate and Fortinet VPN products.
-   **Rotate every credential.** Reset all local, administrator and VPN user passwords, and revoke API keys and long-lived tokens.
-   **Enforce multi-factor authentication** on all remote access and administrative logins, without exception.
-   **Review logs** for unexpected successful logins, new accounts, configuration changes, unfamiliar VPN tunnels and traffic to unusual destinations.
-   **Reduce exposure.** Restrict management interfaces to trusted networks and place VPN portals behind additional access controls.

## The offline alternative

The Fortinet campaign is a reminder that every internet-connected control is, in the end, reachable. Perimeter devices can be patched, hardened and monitored, but they cannot be made unreachable while they remain online. Firevault takes a different approach at the storage layer. Data protected by **Layer 1 [physical air gap](/offline-secure-storage/what-is-oss) storage** is physically disconnected from any network by default, so a stolen VPN credential, a compromised firewall or an attacker moving laterally through the estate has no route to it. The perimeter can fail, and the crown-jewel data still cannot be read, exfiltrated or encrypted.

## Key takeaways

-   **Assume exposure.** If Fortinet VPN or firewall management has been reachable from the internet, check with a FortiBleed asset checker and treat any hit as a compromise.
-   **Credentials are the currency.** The leaked database exists because passwords were reused and rarely rotated. Multi-factor authentication and unique credentials remove most of the value.
-   **Perimeter controls are not a last line of defence.** They are the first line, and they will occasionally fall. Plan for that reality.
-   **Air gap the data that must not be lost.** If it is not on the network, it cannot be reached through a compromised firewall or VPN.

_Analysis by Mark Fermor, Firevault._

About the author

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)[

![Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg)

Breach Analysis 

### Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust

Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that knocked passengers off the aircraft network. The lesson is not about aviation. It is about how easily a trusted connection can be impersonated.

13 Aug 2026 4 min 







](/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026)[

![Ransomware Attacks Spike 20% in July While AI Steals the Headlines](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg)

Breach Analysis 

### Ransomware Attacks Spike 20% in July While AI Steals the Headlines

Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.

12 Aug 2026 4 min 







](/news/ransomware-attacks-spike-july-2026-ai-distraction)

Share this article

Breach Analysis 8 July 2026 3 min read 

## NCSC warns UK organisations over global Fortinet firewall and VPN credential leak

The National Cyber Security Centre has issued an alert after a threat actor leaked a database of credentials harvested from brute-force and credential-stuffing attacks against internet-facing Fortinet firewalls and VPN gateways. UK organisations using FortiGate or Fortinet VPN portals are urged to investigate exposure and apply mitigations immediately.

![NCSC warns UK organisations over global Fortinet firewall and VPN credential leak](/__l5e/assets-v1/b4a021e4-2b1e-493e-9363-128798186f7b/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak-2x.jpg)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Published by Mark Fermor , Director & Co-Founder 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak&text=NCSC%20warns%20UK%20organisations%20over%20global%20Fortinet%20firewall%20and%20VPN%20credential%20leak%0A%0AThe%20National%20Cyber%20Security%20Centre%20has%20issued%20an%20alert%20after%20a%20threat%20actor%20leaked%20a%20database%20of%20credentials%20harvested%20from%20brute-force%20and%20credential-stuffing%20attacks%20against%20internet-facing%20Fortinet%20firewalls%20and%20VPN%20gateways.%20UK%20organisations%20using%20FortiGate%20or%20Fortinet%20VPN%20portals%20are%20urged%20to%20investigate%20exposure%20and%20apply%20mitigations%20immediately.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak)[](mailto:?subject=NCSC%20warns%20UK%20organisations%20over%20global%20Fortinet%20firewall%20and%20VPN%20credential%20leak&body=The%20National%20Cyber%20Security%20Centre%20has%20issued%20an%20alert%20after%20a%20threat%20actor%20leaked%20a%20database%20of%20credentials%20harvested%20from%20brute-force%20and%20credential-stuffing%20attacks%20against%20internet-facing%20Fortinet%20firewalls%20and%20VPN%20gateways.%20UK%20organisations%20using%20FortiGate%20or%20Fortinet%20VPN%20portals%20are%20urged%20to%20investigate%20exposure%20and%20apply%20mitigations%20immediately.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak)

[Read full article](https://fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/offline-secure-storage/what-is-oss)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)