FortiBleed campaign hits UK government credentials.
Russian-speaking cybercriminals reportedly stole UK government login credentials and offered them for sale on dark-web forums. The affected accounts reportedly include Foreign Office-related users and local government staff, with credentials tied to the wider FortiBleed campaign against Fortinet firewalls and VPN gateways. The UK NCSC had already warned that Fortinet firewalls and VPN gateways were being targeted globally through brute-force, dictionary, and credential-stuffing attacks, and that a credential database had leaked. The concern is that valid perimeter-device and email credentials can be reused for deeper intrusions into government, healthcare, energy, and other critical services. The report says organizations were urged to review affected networks and isolate compromised devices