Over the past few days, a large-scale campaign has emerged targeting Fortinet firewalls and SSL VPN services. Security researchers have identified almost 74,000 internet facing Fortinet devices that may be exposed, with attackers using stolen usernames and passwords to attempt access at scale.
The headlines are focused on Fortinet, with organisations such as the BBC, DHL, Spotify, Samsung, Oracle and Sony all reported to be in the firing line. But the wider story is bigger than one vendor. Businesses of every size and from every sector are being targeted, from global brands through to local SMEs, all because attackers are looking for exposed services, weak credentials and opportunities to reuse passwords that have already been compromised elsewhere.
The National Cyber Security Centre has been clear that this is a credible and active threat, with potential impact in the UK, and is urging organisations to investigate whether they may be affected and to strengthen how access into their systems is controlled.
To make sense of this, it helps to understand a few of the terms involved.
A firewall is the main barrier between an organisation’s internal systems and the outside world. It controls what is allowed in and out, and plays a central role in keeping systems protected from unwanted access.
A VPN, or virtual private network, is a secure way for people to connect into work systems when they are not in the office. It creates a private connection over the internet, so someone working from home can access files, applications and systems as if they were sat at their desk.
An SSL VPN is one specific type of VPN that has been widely used for many years. It is simple to set up and familiar to users, which is why it remains in place in many organisations today. However, it sits on the edge of the network, is exposed to the internet and typically relies on usernames and passwords as the main form of authentication.
Internet facing systems are the parts of an organisation’s infrastructure that can be reached directly from the public internet, such as remote access portals and firewalls. They exist for good reason, but because they are accessible from anywhere, they are also the most common target for attackers.
What stands out about this campaign is that it is not about a weakness in the technology itself. Many of the organisations affected are running supported, fully updated systems. The risk sits in how credentials are managed and how remote access is set up, areas that are often shaped by decisions made years ago and quietly left in place since.
Rather than exploiting a flaw, attackers are using large databases of usernames and passwords gathered from unrelated incidents over many years, and quietly testing them against internet facing services at scale. Where credentials still work, they simply log in .
That is why the common factor in who is being targeted is not the technology in use, the sector or size of the organisation or its level of technical maturity. It is whether attackers can find a route in using credentials they already possess.
The uncomfortable reality is that attackers are not trying to break down the door, they are checking whether someone left a key under the mat.
The reason SSL VPN keeps appearing in alerts like this is straightforward. It is one of the most common ways people connect into work systems remotely, which means it is also one of the most exposed. When credentials have been leaked or reused elsewhere, attackers can quietly try them against thousands of organisations at once, looking for a way in.
In many environments, SSL VPN is still in place not because it is the best option, but because it has always been there. As working patterns have changed and threats have evolved, the level of risk attached to that approach has quietly grown.
The Fortinet campaign is a timely reminder to step back and review how remote access and credentials are being managed. There are a number of practical areas worth looking at, including:
These are sensible steps in their own right, but the bigger opportunity is to look beyond the immediate concern and rethink how access is delivered overall.
Our position is straightforward and consistent with what we are seeing across the industry. Organisations should update their firewall platforms to the latest supported version and, just as importantly, move away from SSL VPN wherever possible. Patching remains essential, but on its own it does not address the underlying issue. If access is still being provided through methods that are inherently exposed and reliant on passwords alone, the risk remains.
Where remote access is being reviewed or redesigned, we believe organisations should lead with Global Secure Access (GSA) rather than SSL VPN. GSA is a modern way of enabling secure access to systems, where people are only given access to the specific applications they need, with security checks built in at every stage. Rather than opening a wider connection into the network, it brings access in line with how organisations need to operate today, with stronger controls, better visibility and far less exposure.
We are also proactively reviewing clients using Fortinet firewalls, analysing access logs and carrying out additional validation checks to identify any signs of unauthorised access. We will also contact clients using SSL VPN technology to discuss alternative access methods and reduce potential risk.
While the headlines are focused on Fortinet today, the wider lesson applies to every organisation with internet facing access services.
The question is no longer “are our systems patched?” but is “what happens if an attacker already knows a valid password?”.
The organisations best positioned to defend against modern threats are those that assume passwords alone are no longer enough, and design access around that reality. Modern approaches like Global Secure Access reduce reliance on traditional network-level access and give organisations far tighter control over exactly who can access what, from where and on which device.
By making these foundations stronger now, organisations are not just responding to a single campaign, they are putting themselves in a better position for everything that comes next.
If you are not sure where your organisation stands, we can help you understand your current position, identify any areas of exposure and move towards a more secure, modern approach to remote access.
Talk to Trident about the right next step for your organisation.
Date: 9 December 2025 Time: 10am – 11am Where: Microsoft Teams webinar Hospices are under constant pressure, balancing limited time, stretched resources, and growing demand. AI offers a helping hand to ease that burden: streamlining administrative tasks, saving time, and allowing staff to focus on what truly matters, delivering compassionate patient care. In this session,…
We’re delighted to announce that we have recently become a corporate member of Sussex Wildlife Trust, a respected local charity formed in 1961, and is now the largest local organisation dedicated to protecting the wildlife and natural environment across Sussex. By joining as a corporate member, we’re supporting vital work that helps safeguard local habitats,…
We’re pleased to share that following our latest independent surveillance audit, Trident continues to meet the internationally recognised standards of ISO 27001, a certification we’ve held since 2019. In today’s complex digital world, information security is more than a requirement, it’s a responsibility. Our ISO 27001 certification reflects our ongoing commitment to safeguarding our systems,…
Hospices face growing cybersecurity risks, often with limited internal IT capacity. Our services are designed to support your team with additional insight, helping you stay secure without adding pressure. To do this, we’ve developed a two-part security review service tailored specifically for hospices. Why two parts? Because securing Microsoft 365 isn’t just about getting the…
This past Saturday, our team proudly took to the water at Tilgate Park for St Catherine’s Hospice‘s annual Dragon Boat Race! With paddles in hand and team spirit in full force, we joined 18 other teams in a series of races, each crew battling it out on the water with determination whilst being cheered on…
Microsoft has confirmed that support for Windows 10 will officially end on 14 October 2025. To ease the transition, they’ve introduced an Extended Security Updates (ESU) program, available to all organisations for a fee, but offered free for one year to charities and education providers.
Yesterday, we hosted a fantastic fundraiser quiz night in support of our upcoming dragon boat race for St Catherine’s Hospice on 6th September – and what a night it was!
Trident offers a zero-cost, zero commitment review that assesses an organisation’s IT, focusing on the use of Microsoft 365.
Cybersecurity is no longer just an IT issue. It is a business-critical priority. For C-suite/board members/senior leadership teams, the key question is not if a cyber threat will happen, but how well your organisation is prepared to handle it.
Cyber threats don’t wait, and neither should your defences. By taking five focused actions, you can immediately reduce your exposure, strengthen your resilience, and build confidence in your organisation’s ability to respond. And with Trident as your partner, you gain access to expert support, proven tools, and ongoing guidance, so your internal team can stay focused while we help you stay secure. And here’s where to start.
