Over the past few days, a large-scale campaign has emerged targeting Fortinet firewalls and SSL VPN services. Security researchers have identified almost 74,000 internet facing Fortinet devices that may be exposed, with attackers using stolen usernames and passwords to attempt access at scale.
The headlines are focused on Fortinet, with organisations such as the BBC, DHL, Spotify, Samsung, Oracle and Sony all reported to be in the firing line. But the wider story is bigger than one vendor. Businesses of every size and from every sector are being targeted, from global brands through to local SMEs, all because attackers are looking for exposed services, weak credentials and opportunities to reuse passwords that have already been compromised elsewhere.
The National Cyber Security Centre has been clear that this is a credible and active threat, with potential impact in the UK, and is urging organisations to investigate whether they may be affected and to strengthen how access into their systems is controlled.
To make sense of this, it helps to understand a few of the terms involved.
A firewall is the main barrier between an organisation’s internal systems and the outside world. It controls what is allowed in and out, and plays a central role in keeping systems protected from unwanted access.
A VPN, or virtual private network, is a secure way for people to connect into work systems when they are not in the office. It creates a private connection over the internet, so someone working from home can access files, applications and systems as if they were sat at their desk.
An SSL VPN is one specific type of VPN that has been widely used for many years. It is simple to set up and familiar to users, which is why it remains in place in many organisations today. However, it sits on the edge of the network, is exposed to the internet and typically relies on usernames and passwords as the main form of authentication.
Internet facing systems are the parts of an organisation’s infrastructure that can be reached directly from the public internet, such as remote access portals and firewalls. They exist for good reason, but because they are accessible from anywhere, they are also the most common target for attackers.
What stands out about this campaign is that it is not about a weakness in the technology itself. Many of the organisations affected are running supported, fully updated systems. The risk sits in how credentials are managed and how remote access is set up, areas that are often shaped by decisions made years ago and quietly left in place since.
Rather than exploiting a flaw, attackers are using large databases of usernames and passwords gathered from unrelated incidents over many years, and quietly testing them against internet facing services at scale. Where credentials still work, they simply log in .
That is why the common factor in who is being targeted is not the technology in use, the sector or size of the organisation or its level of technical maturity. It is whether attackers can find a route in using credentials they already possess.
The uncomfortable reality is that attackers are not trying to break down the door, they are checking whether someone left a key under the mat.
The reason SSL VPN keeps appearing in alerts like this is straightforward. It is one of the most common ways people connect into work systems remotely, which means it is also one of the most exposed. When credentials have been leaked or reused elsewhere, attackers can quietly try them against thousands of organisations at once, looking for a way in.
In many environments, SSL VPN is still in place not because it is the best option, but because it has always been there. As working patterns have changed and threats have evolved, the level of risk attached to that approach has quietly grown.
The Fortinet campaign is a timely reminder to step back and review how remote access and credentials are being managed. There are a number of practical areas worth looking at, including:
These are sensible steps in their own right, but the bigger opportunity is to look beyond the immediate concern and rethink how access is delivered overall.
Our position is straightforward and consistent with what we are seeing across the industry. Organisations should update their firewall platforms to the latest supported version and, just as importantly, move away from SSL VPN wherever possible. Patching remains essential, but on its own it does not address the underlying issue. If access is still being provided through methods that are inherently exposed and reliant on passwords alone, the risk remains.
Where remote access is being reviewed or redesigned, we believe organisations should lead with Global Secure Access (GSA) rather than SSL VPN. GSA is a modern way of enabling secure access to systems, where people are only given access to the specific applications they need, with security checks built in at every stage. Rather than opening a wider connection into the network, it brings access in line with how organisations need to operate today, with stronger controls, better visibility and far less exposure.
We are also proactively reviewing clients using Fortinet firewalls, analysing access logs and carrying out additional validation checks to identify any signs of unauthorised access. We will also contact clients using SSL VPN technology to discuss alternative access methods and reduce potential risk.
While the headlines are focused on Fortinet today, the wider lesson applies to every organisation with internet facing access services.
The question is no longer “are our systems patched?” but is “what happens if an attacker already knows a valid password?”.
The organisations best positioned to defend against modern threats are those that assume passwords alone are no longer enough, and design access around that reality. Modern approaches like Global Secure Access reduce reliance on traditional network-level access and give organisations far tighter control over exactly who can access what, from where and on which device.
By making these foundations stronger now, organisations are not just responding to a single campaign, they are putting themselves in a better position for everything that comes next.
If you are not sure where your organisation stands, we can help you understand your current position, identify any areas of exposure and move towards a more secure, modern approach to remote access.
Talk to Trident about the right next step for your organisation.
“I like to believe that working together with Trident, we are far more assured than we’ve ever been as to our own resilience, security and safety, which is a tremendous boon to our reputation.” – Giles Tomsett, Chief Executive at St Catherine’s Hospice In this case study video, St Catherine’s Hospice shares how working in…
At a glance Sussex Wildlife Trust (SWT) partnered with us to successfully relocate from their long-standing premises of over 60 years into a modern office environment built around flexibility, collaboration, and sustainable working practices. This move formed a key milestone within a broader IT roadmap designed to modernise SWT’s technology environment and bring systems and…
In today’s fast-moving digital environment, organisations need strong technology leadership to stay competitive, manage risk, and scale effectively. But for many organisations, hiring a full-time IT director isn’t always practical, or necessary. A fractional IT director offers an alternative: experienced, strategic technology leadership delivered on a flexible basis. Instead of committing to a permanent executive…
At a glance YMCA DownsLink Group, the leading charity for children and young people in Sussex and Surrey, transformed its operations by partnering with Trident to modernise its IT environment. Moving from outdated, on-premises servers to a secure, cloud-based infrastructure, YMCA DLG benefited from dedicated on-site IT support, cybersecurity improvements, (including Cyber Essentials PLUS certification),…
We’re excited to announce that Trident is sponsoring the Under-14s Academy team at Bognor Regis Town Football Club, as well as one of their talented defenders, Liam H. We’re incredibly proud to support such a dedicated young team and to be part of their journey this season. We wish the entire squad great success on…
Microsoft has introduced significant changes to its New Commerce Experience (NCE) licensing offering – and these updates aren’t just about pricing. They’re about giving organisations more flexibility, better security, enhanced productivity, stronger compliance, accelerate AI adoption, and opportunities to optimise spend. Understanding these changes now means you can make informed decisions that protect your budget and strengthen your IT strategy. …
As the year draws to a close, the festive season is always a time for celebration, but for us at Trident, it’s also a time to give back to the community that means so much to us. While we enjoyed plenty of seasonal cheer, from hot chocolates delivered by our very own Santa to laughter-filled…
At a glance – Enhanced system performance post-Citrix migration Tectrans, a global translation specialist, transformed its business by moving from a restrictive Citrix-hosted IT setup to a secure, flexible Microsoft 365 cloud environment. This shift delivered immediate cost savings, improved productivity, and enabled the team to deliver exceptional service to their clients worldwide. About Tectrans…
Hospices are under constant pressure, balancing limited time, stretched resources, and growing demand. AI offers a helping hand to ease that burden: streamlining administrative tasks, saving time, and allowing staff to focus on what truly matters, delivering compassionate patient care. In this session, Louis Graham, Microsoft Copilot Specialist, shared how Microsoft Copilot is being used in…
Hear from Giles Tomsett, Chief Executive at St Catherine’s Hospice, and Stuart Palma, Chief Executive Officer at Southern Hospice Group, on challenges they face in the hospice sector, and how Trident has partnered with them to solve their IT challenges.
