Hackers have acquired passwords to crack firewalls of tens of thousands of devices and networks that include more than 250 maritime- and offshore energy-related companies
Fortinet Firewall passwords and logins were leaked in the recent FortiBleed incident leaving networks and data vulnerable to criminal gangs and bad state actors.
A cybersecurity provider has warned the maritime and offshore energy sectors that hackers are gaining unauthorised access to Fortinet devices, enabling them to further compromise targeted networks and digital information.
More than 86,000 administrator credentials of Fortinet firewalls, virtual private networks (VPNs) and other devices protecting these networks were breached, according to Cydome.
Its research found that the leak represented around 50% of all internet-reachable FortiGate devices, including 703 satellite-linked IP addresses associated with maritime satellite communications providers.
Cydome said more than 250 companies involved in maritime, ports and energy, particularly shipowners and managers, would be far more vulnerable to cyber breaches due to the password leaks.
“FortiBleed is hitting the operational core of maritime trade, not just back-office IT,” said Cydome founder and chief executive Nir Ayalon.
“Of all maritime-related logins leaked, 41.5% were shipping and freight companies, 31.2% were offshore contractors and service companies, 10.7% were shipyards, and 6.7% were port authorities and logistics firms,” he said.
Part of the issue is the general trend worldwide for not updating or changing passwords regularly on legacy devices that are often poorly maintained.
Around 87% of Fortinet devices exposed to the internet still had internet-facing management interfaces available, while 63% of harvested credentials related to default or built-in administrator accounts that had never been renamed.
“This suggests that many organisations have not yet taken the steps needed to fully secure affected systems… probably because they do not know they have been hacked, yet.” said Mr Ayalon.
FortiBleed differs from many cyber incidents because it is not based on a newly discovered software vulnerability.
Instead, it exploits older administrator credentials that remained vulnerable after software upgrades.
In many cases, organisations updated their systems but did not take all the necessary steps to fully replace and discard legacy passwords, allowing attackers to recover valid credentials and test them against live devices - even after the Fortinet software patch.
Frequency of cyber incidents and emergence of new threats is accelerating in 2026 with much of the maritime and offshore energy sectors vulnerable to attacks and security breaches.
According to the US Coast Guard (USCG), there was a 71% year-over-year increase in maritime cyber incidents stemming from stolen or compromised credentials in 2025.
In its Cyber Trends and Insights in the Marine Environment report, the US maritime administration said shipowners, operators and managers were unaware of the vulnerability of their assets and potential for cyber incidents on vessels.
The USCG’s teams discovered default credentials on over two-thirds of boarded vessels, exposing widespread authentication vulnerabilities across shipboard IT networks.
Its analysis highlighted multiple supply-chain risks linked to Chinese-manufactured ship-to-shore cranes.
The USCG also explained how the rapid expansion of satellite connectivity continues to broaden the overall attack surface between vessel systems and corporate shoreside environments.
Another warning came from the Cybersecurity and Infrastructure Security Agency (CISA) that highlighted the vulnerability of automation systems to cyber threats.
CISA said there was heightened risk from Iranian-backed criminals exploiting thousands of internet-exposed industrial control devices, including on infrastructure linked to maritime logistics and port utilities.
Attackers are manipulating operational SCADA display data and stealing project files from compromised logic controllers frequently used in automation and operational technology.
Rapid response
CISA and the UK’s National Cyber Security Centre (NCSC) have urged organisations using Fortinet services to react quickly by introducing robust credential rotation across all affected networks.
“Organisations using Fortinet edge devices with SSL VPN enabled should investigate potentially malicious activity on the device and monitor their network for unusual activity,” said the NCSC.
They should determine if their Fortinet devices are compromised by looking for common indicators of compromise, including unauthorised account creation and unexpected activity in log files.
If organisations find any evidence of compromise they should immediately isolate the device from the internet and an internal network, then report the potential security breach and consider employing a cyber-incident response provider.
“Factory reset the device, as changing credentials alone may not be sufficient if threat actors have obtained persistence on the device,” said the NCSC.
“Ensure you have obtained logs, configs and other artefacts from the device useful for investigations which will be destroyed during the factory reset process.”
Organisations should also investigate other edge devices that share credentials with the compromised device and “monitor firewall logs for suspicious activity in order to obtain assurance that onward compromise within your network has not occurred,” said the NCSC.
“Change all default, generic or reused administrator passwords"
Once any compromise has been fixed, networks need to be re-commissioned and cyber-hardened by ensuring management interfaces are not exposed to the internet, all firmware and software are updated to the latest version and support systems are removed as soon as possible.
“Change all default, generic or reused administrator passwords, ensure multi-factor authentication is enforced on all VPN and device management logins,” said the NCSC.
Cydome co-founder and vice president Alon Ayalon said organisations should “terminate active administrator and VPN sessions, reset passwords, enable multi-factor authentication and investigate systems for signs of unauthorised access.”
Maritime and offshore energy companies can check if their domain or IP addresses are included by using the free tool at fortibleedcheck.cydome.io.
Mr Ayalon said the FortiBleed incident highlights how vulnerable the maritime industry is to cyber threats due to legacy networks and administration and recent surge in high-speed satellite communications.
“If attackers obtain trusted administrator access, they can move through networks unnoticed, gain control over operational systems or sell the information to ransomware groups and other cybercriminals,” he said.
“Protecting digital identities is just as important as protecting the IT and OT systems themselves.”
Events
© 2026 Riviera Maritime Media Ltd.