Over the past few days, a large-scale campaign has emerged targeting Fortinet firewalls and SSL VPN services. Security researchers have identified almost 74,000 internet facing Fortinet devices that may be exposed, with attackers using stolen usernames and passwords to attempt access at scale.
The headlines are focused on Fortinet, with organisations such as the BBC, DHL, Spotify, Samsung, Oracle and Sony all reported to be in the firing line. But the wider story is bigger than one vendor. Businesses of every size and from every sector are being targeted, from global brands through to local SMEs, all because attackers are looking for exposed services, weak credentials and opportunities to reuse passwords that have already been compromised elsewhere.
The National Cyber Security Centre has been clear that this is a credible and active threat, with potential impact in the UK, and is urging organisations to investigate whether they may be affected and to strengthen how access into their systems is controlled.
To make sense of this, it helps to understand a few of the terms involved.
A firewall is the main barrier between an organisation’s internal systems and the outside world. It controls what is allowed in and out, and plays a central role in keeping systems protected from unwanted access.
A VPN, or virtual private network, is a secure way for people to connect into work systems when they are not in the office. It creates a private connection over the internet, so someone working from home can access files, applications and systems as if they were sat at their desk.
An SSL VPN is one specific type of VPN that has been widely used for many years. It is simple to set up and familiar to users, which is why it remains in place in many organisations today. However, it sits on the edge of the network, is exposed to the internet and typically relies on usernames and passwords as the main form of authentication.
Internet facing systems are the parts of an organisation’s infrastructure that can be reached directly from the public internet, such as remote access portals and firewalls. They exist for good reason, but because they are accessible from anywhere, they are also the most common target for attackers.
What stands out about this campaign is that it is not about a weakness in the technology itself. Many of the organisations affected are running supported, fully updated systems. The risk sits in how credentials are managed and how remote access is set up, areas that are often shaped by decisions made years ago and quietly left in place since.
Rather than exploiting a flaw, attackers are using large databases of usernames and passwords gathered from unrelated incidents over many years, and quietly testing them against internet facing services at scale. Where credentials still work, they simply log in .
That is why the common factor in who is being targeted is not the technology in use, the sector or size of the organisation or its level of technical maturity. It is whether attackers can find a route in using credentials they already possess.
The uncomfortable reality is that attackers are not trying to break down the door, they are checking whether someone left a key under the mat.
The reason SSL VPN keeps appearing in alerts like this is straightforward. It is one of the most common ways people connect into work systems remotely, which means it is also one of the most exposed. When credentials have been leaked or reused elsewhere, attackers can quietly try them against thousands of organisations at once, looking for a way in.
In many environments, SSL VPN is still in place not because it is the best option, but because it has always been there. As working patterns have changed and threats have evolved, the level of risk attached to that approach has quietly grown.
The Fortinet campaign is a timely reminder to step back and review how remote access and credentials are being managed. There are a number of practical areas worth looking at, including:
These are sensible steps in their own right, but the bigger opportunity is to look beyond the immediate concern and rethink how access is delivered overall.
Our position is straightforward and consistent with what we are seeing across the industry. Organisations should update their firewall platforms to the latest supported version and, just as importantly, move away from SSL VPN wherever possible. Patching remains essential, but on its own it does not address the underlying issue. If access is still being provided through methods that are inherently exposed and reliant on passwords alone, the risk remains.
Where remote access is being reviewed or redesigned, we believe organisations should lead with Global Secure Access (GSA) rather than SSL VPN. GSA is a modern way of enabling secure access to systems, where people are only given access to the specific applications they need, with security checks built in at every stage. Rather than opening a wider connection into the network, it brings access in line with how organisations need to operate today, with stronger controls, better visibility and far less exposure.
We are also proactively reviewing clients using Fortinet firewalls, analysing access logs and carrying out additional validation checks to identify any signs of unauthorised access. We will also contact clients using SSL VPN technology to discuss alternative access methods and reduce potential risk.
While the headlines are focused on Fortinet today, the wider lesson applies to every organisation with internet facing access services.
The question is no longer “are our systems patched?” but is “what happens if an attacker already knows a valid password?”.
The organisations best positioned to defend against modern threats are those that assume passwords alone are no longer enough, and design access around that reality. Modern approaches like Global Secure Access reduce reliance on traditional network-level access and give organisations far tighter control over exactly who can access what, from where and on which device.
By making these foundations stronger now, organisations are not just responding to a single campaign, they are putting themselves in a better position for everything that comes next.
If you are not sure where your organisation stands, we can help you understand your current position, identify any areas of exposure and move towards a more secure, modern approach to remote access.
Talk to Trident about the right next step for your organisation.
Signing in is about to get a whole lot safer and simpler. With Microsoft retiring text and phone call authentication codes, here is why passkeys strengthen your defences and how to make the move with confidence. For years, passwords have been the weakest link in almost every organisation’s defences. That is now changing, and the…
Hospices are being asked to do more with technology than ever, from tighter compliance and smarter ways of working to safer systems and a serious conversation around AI. It is a lot to navigate when budgets are tight and teams are stretched. The Southern Hospices Technology Leaders Forum brings together leaders from across the south…
Eight members of the Trident team have successfully completed The Clock Tower Sanctuary’s annual half marathon hike from Lewes to Brighton, raising more than £2,000 to support young people experiencing homelessness across Brighton & Hove. Taking place on 11 July 2026 during sweltering temperatures, the challenge saw the team cover over 13 miles across the…
In many hospices, internal communications have grown organically over time. Policies are shared as email attachments, news goes out across multiple channels, and teams across clinical, fundraising and operations often have their own ways of storing and sharing information. This approach works in practice, but over time it can make it harder for people to…
“Working with Trident gives reassurance which is important for me, for our board, and for our people here at Southern Hospice Group.” – Stuart Palma, Chief Executive Officer at Southern Hospice Group Confidence, clarity and continuity are critical during any merger. In this case study video, Southern Hospice Group shares how partnering with Trident helped…
Upcoming event: Southern Hospices Technology Leaders Forum 23 September 2026 | 8:30am – 2pm | Leonardslee Lakes & Gardens The Southern Hospices Technology Leaders Forum brings together leaders from across the south for a half-day event focused on the topics shaping hospice technology right now. Expect expert-led sessions on compliance, AI and cyber security, plus an…
On 11 July, eight members of the Trident team will take on The Clock Tower Sanctuary’s annual half marathon hike from Lewes to Brighton, raising funds and awareness to support young people experiencing homelessness across Brighton and Hove. The team is aiming to raise £1,600 to help The Clock Tower Sanctuary continue providing vital support…
30 June 2026 | 10am – 11am | Microsoft Teams In many hospices, internal communications have grown organically over time. Policies are shared as email attachments, news goes out across multiple channels, and teams across clinical, fundraising and operations often have their own ways of storing and sharing information. This approach works in practice, but…
Modern organisations rely heavily on digital systems to support day‑to‑day operations. Cloud platforms, connected devices and integrated applications now play a central role in how teams communicate, collaborate and deliver services. As a result, IT environments have become larger, more interconnected and constantly active. Systems generate continuous activity across users, devices, networks and cloud services, making it increasingly difficult to recognise when something unusual is…
As IT environments have become more interconnected and the risk landscape has changed, Trident has extended its Monitoring and Protection Service with the introduction of MPS Pro. MPS Pro builds on Trident’s well-established monitoring and protection capability by adding 24/7 managed detection and response; Activity across environments is continuously monitored, reviewed and actioned by Trident’s security specialists, providing…
