Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

CISA reported that global reports associated leaked credentials with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. That figure establishes a reported association with exposed credentials—not that 74,000 devices were successfully accessed or that their organizations were breached. CISA’s June 18, 2026 advisory does not disclose the underlying dataset or how it counted and deduplicated devices. CISA’s advisory and Fortinet’s June 19 analysis serve different roles: CISA reports the figure and gives defensive guidance; Fortinet offers the vendor’s initial assessment of the activity.

What does the approximately 74,000 figure mean?

CISA’s June 18, 2026 advisory says global reports associated leaked credentials with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. The figure is CISA’s description of what those reports associated with exposed credentials. The advisory does not publish the underlying dataset, collection procedure, or deduplication method, so the figure should remain attributed to CISA and qualified as approximate.

It is not a count of confirmed successful intrusions. A count can describe what a source associated with a dataset under its own definitions and collection window; the number alone does not show that every record represents a unique device, that its credentials were still valid, or that anyone used them to gain access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the count cannot establish on its own

Moving from reported exposure to confirmed compromise requires device-specific evidence. CISA’s advisory recommends examining operational evidence rather than treating the headline figure as proof about every device.

#1 Best Overall
Sale
FortiGate-40F Network Security Appliance Plus 3 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-40F-BDL-950-36)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 3 years of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.
  • Unique devices: The advisory does not explain whether repeated records for one device were collapsed.
  • Current credential validity: It does not say that every reported credential was tested and found usable when reported.
  • Successful access: A credential’s appearance in reports does not establish that an attacker authenticated to a particular device.
  • Downstream impact: The count does not establish unauthorized configuration changes, access to an organization’s wider network, or other post-access activity.

Evidence that can help establish what happened at a specific organization includes firewall, VPN, authentication, and domain-controller logs; suspicious account creation; unauthorized configuration changes; and other corroborating incident indicators. The evidentiary distinction matters: exposure, attempted authentication, successful access, and confirmed downstream compromise are different claims.

How to read Fortinet’s assessment alongside CISA’s advisory

CISA’s June 18 advisory reports the approximate device figure and recommends hardening and investigation. Fortinet’s June 19, 2026 analysis presents the vendor’s initial assessment of the activity. Fortinet said it involved reuse of credentials from earlier incidents and brute-force activity against devices with weak password hygiene and no MFA. It stated: “This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory.”

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

That is Fortinet’s assessment, not independent verification of the provenance of every credential associated with the reports. It should not be recast as proof that every listed credential came from a particular earlier incident, or as proof that no listed device was compromised. The two publications answer different questions: CISA conveys a reported exposure figure and response guidance, while Fortinet describes its own initial view of the campaign.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the metric’s unit and definition matter

Exposure figures are only comparable when their units and definitions match. Fortinet’s FortiWeb Cloud 24.1.0 documentation defines its “Credential Exposure” indicator as email addresses related to organizational domains that appear in third-party credential breaches. Its separate “Stealer Infection” indicator concerns potentially infected affiliated systems whose data is leaked or for sale. These are product-dashboard categories, not interchangeable counts of confirmed intrusions—and they do not establish the method used for CISA’s FortiGate-device figure. Fortinet’s documentation describes those indicators in that product context.

Rank #3
FortiGate-40F Network Security Appliance Plus 1 Year FortiGuard Enterprise Protection and FortiCare Premium (FG-40F-BDL-809-12)
  • Complete Security and Hardware Offering: Includes FortiGate-40F with 1 year of FortiCare Premium and FortiGuard Enterprise Protection.
  • Comprehensive Enterprise Services: Features advanced services such as CASB, DLP, IoT security measures, and attack surface assessments.
  • Enhanced Threat Detection and Prevention: Integrates AI-based malware prevention for proactive security measures.
  • Robust Support Network: FortiCare Premium offers access to technical expertise for optimal device operation and security management.
  • Suitable for Varied Environments: Ideal for environments requiring detailed and layered security approaches.

When evaluating another exposure report, check the following before comparing its number with CISA’s:

  • Unit counted: Devices, accounts, email addresses, credentials, or records?
  • Population and scope: Which products, services, organizations, and geographies are included?
  • Time window: When was the data collected, and how old might the underlying credentials be?
  • Deduplication: Were multiple records for one device or account combined?
  • Validation: Were credentials tested as current, or merely observed in a dataset?
  • Evidence level: Does the source show exposure, attempted authentication, successful access, or confirmed downstream compromise?
  • Attribution: Is the statement from a vendor, an agency summarizing third-party reporting, or the original dataset publisher?

The available CISA advisory does not provide enough methodological detail to answer all these questions about the approximately 74,000-device figure. That uncertainty is a reason to avoid stronger claims, not a basis for guessing how the underlying reports were assembled.

Rank #4
FORTINET | FG-100E | FortiGate-100E Network Security Appliance
  • Protects against known exploits, malware and malicious websites; detects unknown attacks; identify thousands of applications
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations should do with the alert

The reported count is not a diagnosis of any individual organization’s environment. CISA and Fortinet provide practical response guidance; organizations should apply it alongside their own logs and incident-response procedures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. End active sessions and change credentials. CISA recommends terminating active SSL VPN and administrative sessions and resetting Fortinet VPN and administrative passwords.
  2. Review administrator credential storage. Confirm PBKDF2 is used for administrator credential storage and remove weaker legacy hashes in line with Fortinet guidance. Fortinet also advises using supported software versions that support PBKDF2.
  3. Inspect relevant logs and configurations. Review firewall, VPN, authentication, and domain-controller logs for suspicious activity, and compare device configuration with a known-good baseline.
  4. Strengthen authentication and limit exposure. Enable phishing-resistant MFA for remote-access and administrative accounts. Remove public internet access to firewall administration or restrict it to trusted internal networks.
  5. Escalate when there are indicators of compromise. Fortinet advises treating devices as compromised and following recovery guidance if there is evidence of unauthorized configuration modification or other indicators.

These steps are recommendations from CISA and Fortinet, not evidence that every device associated with the reported exposure was compromised. A physical FIDO2 security key can be one way to implement phishing-resistant MFA where the organization’s identity provider and deployment support it.

Best Value
FortiGate-30G Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-30G-BDL-950-12)
  • Single appliance with integrated firewalling, SD-WAN and Wi-Fi controller reduces complexity of WLAN management. Its zero-touch deployment helps optimize your onboarding experience.
  • Built on a patented secure processor, this compact network firewall delivers the highest level of security and performance in its class – 800 Mbps IPS | 500 Mbps threat protection.
  • User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
  • Compact and fanless design equipped with 4 GE RJ45 ports (1 WAN port and 3 internal ports) provide essential connectivity and flexibility for various network configurations in a small-scale environment.
  • Including award-winning FortiGate hardware and 1-year FortiGuard AI-powered UTP security services. Services cover IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium customer support.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.