Features
We need to talk about passwords
How did credentials become the most common control in the business and still the one nobody is managing properly?
03 August 2026
In June 2026, a round 75 000 Fortinet firewalls, or around half of every Fortinet device facing the internet, had their admin passwords cracked. The company had fixed the underlying weakness over a year earlier. The passwords were initially stored using SHA-256, a fast-hashing algorithm. Any attacker with enough GPU power could easily run millions of guesses a second until one matched. The replacement algorithm, PBKDF2, slows that process down, but the upgrade wasn’t automatic. It only applied the next time an admin logged in and triggered it, and most never did.
The incident, which quickly became known as “FortiBleed”, is one of the largest credential exposures tied to a single vendor, and shows how length and complexity protect nothing once an attacker has the plaintext in hand. And in this particular scenario, 20-character strings were just as vulnerable as “password123”, a reminder that no password is strong enough to survive sitting unrotated, unchecked and forgotten. Fortinet did its part, but what it couldn’t do is force someone to log into their own firewall and trigger the fix.
ITWeb Premium
Get 3 months of unlimited access
No credit card. No obligation.
