Hackers leak a list of ~500K Fortinet VPN login names and passwords; a source in the IT security industry says at least some of the leaked credentials are valid
A threat actor has leaked a list of almost 500,000 Fortinet VPN login names and passwords that were allegedly scraped from exploitable devices last summer.
Context & Ripple Effects
This dump extends a pattern that has been building for years: a hacker posted usernames, passwords and SSH keys for 900+ Pulse Secure VPN servers on a Russian-speaking forum in 2020, and researchers had earlier found older Fortinet firewall versions reachable via a hard-coded password back in 2016. Edge VPN appliances keep leaking credentials at scale.
What makes this one worse than a routine scrape is the industry source saying at least some of the ~500K credential pairs are still valid — turning a historical vulnerability archive into a live intrusion kit for anyone targeting Fortinet VPN users.
First-order effects
- Organizations running exposed Fortinet SSL-VPN endpoints face immediate account-takeover risk and need to force password resets and audit VPN logs for logins matching the leaked list.
- Threat actors gain pre-validated entry points into corporate networks, skipping exploit development entirely where credentials check out.
Second-order effects
- Expect a wave of credential-stuffing against Fortinet and comparable VPN gateways, mirroring the post-disclosure attack surge against Pulse Secure and Fortinet services in 2019.
- Enterprises will accelerate mandatory multi-factor authentication on remote-access VPNs, and security teams will pressure vendors like Fortinet over how long exploitable device configurations remain unpatched in the wild.
Third-order effects
- If appliance-scraped credential dumps keep recurring — as they did again in the 2026 leak exposing FortiGate credentials for 73,932 firewall URLs across 194 countries — password-based VPN access becomes structurally untenable, pushing enterprises toward phishing-resistant MFA and zero-trust architectures.
- Vendors of edge security appliances face a compounding reputational liability: every past vulnerability becomes a renewable credential source, raising the bar for patch telemetry and customer notification practices — an area where Fortinet was later criticized for privately sitting on the critical FortiManager API flaw before disclosing it.
The trend: Enterprise VPN credentials are becoming a traded commodity on hacker forums, steadily eroding password-based perimeter access in favor of zero-trust authentication.