Skip to content
The Cyber Security Place

86,000 of the same box, in 194 countries, all at once

Event dated 24 June 2026 · Published 2 September 2026 · 3 sources

Researchers described a campaign in June 2026 collecting login credentials from more than 86,000 internet-facing FortiGate firewalls across 194 countries. Nothing was injected into the vendor and no update was poisoned, so this is not supply chain compromise in the usual sense. It is something plainer and harder to fix: when a large share of the world buys the same appliance for the same job, a single weakness in it becomes a simultaneous event rather than a series of separate incidents. The install base is the blast radius, and no individual buyer chose it.

Supply chain risk is normally discussed as contamination. Somebody compromises a build system, a malicious update ships, and the trust customers placed in a vendor is used against them. It is the right thing to worry about and it is not what happened here.

Here the vendor shipped what it meant to ship. What made the month notable is arithmetic: the same product, doing the same job, exposed to the internet in the same way, at a scale where one technique reaches nearly every instance in the world within days.

A risk that only exists in aggregate

For any single organisation, choosing a widely deployed appliance from a large vendor is the defensible decision. It is well documented, staff can be hired who know it, patches arrive, and the vendor will still exist in five years. Every one of those reasons is sound.

The risk appears only when the same sound reasoning is applied by everybody simultaneously. Nobody chose the monoculture; it is the sum of a hundred thousand individually correct procurement decisions, and no participant can see it from where they stand.

Why credential harvesting is the worst outcome here

A campaign that took down 86,000 firewalls would be an emergency with a clear end: the outage is visible, the response is obvious, and recovery is measurable. Collecting credentials produces no outage at all, and leaves 86,000 organisations in a state they cannot detect from the outside.

The harvest is not the incident. It is the precondition for however many incidents follow later, using valid credentials against systems the firewall was protecting — which, as February's national registry showed, is the class of intrusion that produces nothing for a detection tool to recognise.

What a single organisation can still do

Assume the credentials on any internet-facing appliance are known, and rotate them on that assumption rather than on confirmation, because confirmation is not coming. That includes local administrative accounts, which are the ones typically excluded from rotation schedules on the grounds that nothing reaches them.

Longer term, the only structural answer is diversity somebody deliberately pays for: not running the same product at every layer of the path an attacker would take. It costs more and it is the one measure that survives the next flaw in whatever everybody bought.