Thousands of leaked logins put maritime networks at risk
Cydome’s threat-intelligence unit reports that major maritime, ports, and energy organizations have been affected by a “FortiBleed” incident involving leaked Fortinet Firewall credentials.
The dataset exposed more than 86,000 administrator logins tied to Fortinet devices across thousands of organizations in 194 countries, enabling potential unauthorized access to networks and downstream systems. The research indicates the scope is significant in the maritime sector, including 703 satellite-linked IP addresses tied to maritime communications providers. Among more than 250 impacted maritime firms, most were shipowners or ship management companies.
Of the specific companies involved, more than 40% are shipping companies, consistent with FortiBleed hitting the operational core of the sector, not just back-office IT.
The breakdown shows 41.5% shipping and freight operators, 31.2% offshore contractors and service firms, 10.7% shipyards (newbuild and repair), and 6.7% port authorities and logistics organizations. Cydome says this suggests the issue is affecting operational infrastructure in maritime trade, not just administrative IT systems.
A key concern is that 87% of exposed Fortinet devices reportedly still had internet-facing management interfaces enabled, while 63% of the leaked credentials were default or built-in administrator accounts that had never been renamed. According to Cydome, this suggests many organizations may not yet realize they have been exposed, particularly because the incident stems from reused or lingering credentials rather than a newly discovered software vulnerability.
What is FortiBleed?
As explained by Cydomre, FortiBleed is the name for a large-scale cyber campaign to gain unauthorized administrative access to Fortinet security devices (internet-facing Fortinet FortiGate firewalls and SSL-VPN gateways), leveraging that access for reconnaissance and further exploitation of the target networks.
FortiBleed exploits a flaw in how Fortinet stored saved device login passwords. In the past, they used a weak algorithm that could have been cracked using brute force with modern GPUs quite quickly. Fortinet later upgraded their algorithm from the end of 2024 to mid-2025, but the old hash file was not deleted, and FortiBleed hackers leveraged this legacy file to try and brute-force their way in. The hackers tried known, commonly used or breached credentials – whichever way worked faster.
Unlike a traditional exploit, FortiBleed is described as leveraging older administrative credentials that remained valid even after system upgrades and patches. In some cases, organizations updated software but failed to fully rotate or retire legacy passwords, allowing attackers to test recovered credentials against live systems.
Commenting on the seriousness of the incident, Cydome co-founder and VP R&D Alon Ayalon said it has already prompted action from the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
We urge organizations to follow the CISA guidance and terminate active administrator and VPN sessions, reset passwords, enable multi-factor authentication and investigate systems for signs of unauthorized access
… said Alon Ayalon.
Content Original Link:
" target="_blank">

