The Cyber Security Authority (CSA) has issued a technical advisory cautioning organisations about a large-scale cybercrime campaign known as "FortiBleed" that is actively targeting Fortinet FortiGate firewalls and SSL VPN gateways.
According to the Authority, the campaign is exploiting weak credential practices to gain unauthorised access to exposed systems across multiple sectors.
The advisory, issued on June 19, noted that the threat does not rely on a newly discovered software vulnerability but instead takes advantage of password reuse and the absence of multi-factor authentication (MFA).
In the statement, the CSA said threat actors are using automated tools to scan internet-facing Fortinet devices and test them against databases of previously leaked credentials.
“A large-scale cybercrime campaign, known as ‘FortiBleed,’ is actively targeting Fortinet FortiGate firewalls and SSL VPN Gateways. The campaign leverages credential harvesting and password-spraying techniques to gain unauthorised access to exposed systems,” the Authority said.
The CSA explained that once attackers gain access, they may be able to monitor network traffic, capture authentication data and establish long-term access to compromised systems.
For anyone managing several online accounts, an antidetect browser gives each profile its own device fingerprint, so platforms can't link or flag them.
According to the advisory, such breaches could enable cybercriminals to move laterally across networks, escalate privileges and compromise critical internal systems, including Active Directory environments.
The Authority noted that organisations are particularly vulnerable where administrative or VPN interfaces are publicly accessible, passwords are weak or repeatedly used, and MFA is not enforced.
It urged institutions to investigate suspicious login activities, repeated failed login attempts followed by successful access, unauthorised administrator accounts and unexpected firewall configuration changes.
“Organisations may be at increased risk if administrative or VPN interfaces are publicly accessible, passwords are reused, weak, or not regularly rotated, and MFA is not enforced for remote or administrative access,” the statement said.
As part of its recommendations, the CSA advised organisations to immediately rotate administrative and VPN credentials, enforce MFA and adopt strong, unique passwords.
It also encouraged institutions to restrict administrative access to trusted IP addresses, disable unnecessary services, continuously monitor authentication logs and implement network segmentation to reduce the impact of potential breaches.





Despair and anger in Conakry after deadly landfill collapse
I will work to ensure Bawumia wins 2028 elections if re-elected NPP General Secr...
GoldBod has made personal attacks a pattern against critics – Akosua Manu
Alleged $1.7bn GoldBod losses: Bawumia backs Minority’s push for accountability
'We have never taken GHS1 billion overdraft from BoG' – GoldBod denies claim by ...
Over 3,500 migrant beggars, illegal immigrants were removed from Ghana in 2025 –...
‘I know the game’ – Osahen Afenyo-Markin shrugs off Sammy Gyamfi’s ‘extortionist...
Court grants former GIIF bosses final extension to file defence in $2m SkyTrain ...
Saglemi project vindicates PPP model, should be mainstreamed for housing deliver...
Domestic Gold Purchasing Programme losses exceed $1.7bn – Prof Bokpin