BERMUDA-INTERNET-Government warns of cybersecurity attack

The Ministry of National Security is urging Bermudians and businesses that operate Fortinet firewall or VPN devices to be aware of the global credential compromise campaign, widely referred to as ‘FortiBleed’ which is actively targeting these devices.

The ministry said acting on advice from the National Cybersecurity Unit (NCU), organisations that have not taken protective action are at risk of unauthorised access to their networks. ‘The security of Bermuda’s digital infrastructure is a matter of national importance. This campaign is not a theoretical risk. It is an active threat that has already compromised tens of thousands of devices globally,’ said Acting Minister of National Security, Jaché Adams.

‘I urge every organisation in Bermuda operating Fortinet equipment to treat this as a priority and act on the guidance provided today without delay,’ Adams added.

FortiBleed is a large-scale credential harvesting campaign targeting Fortinet FortiGate firewalls and SSL VPN gateways exposed to the internet. Security researchers estimate that between 74,000 and 86,000 devices have been affected globally.

Attackers are exploiting previously compromised credentials, password reuse, and automated brute-force tools to gain unauthorised access.

Fortinet has confirmed that this is not a new software vulnerability and that the activity stems from weak password practices, absent multi-factor authentication, and legacy password storage methods that persist on some devices even after firmware updates.

Once inside a device, attackers can intercept network traffic, create backdoor accounts, modify configurations, and move laterally into connected systems, including Active Directory environments.

The U.S. Cybersecurity and Infrastructure Security Agency and Fortinet’s own Product Security Incident Response Team have both issued formal guidance urging immediate action.

The ministry said that any organisation or individual in Bermuda operating a Fortinet FortiGate firewall or SSL VPN gateway, whether in the public sector, private sector, financial services, telecommunications, healthcare, or any other sector, should treat this alert as directly relevant and act immediately.

Fortinet is proactively contacting customers whose devices have been identified as potentially compromised. Organisations that have not received direct notification should not assume their devices are unaffected.

The NCU strongly advises all Fortinet device operators in Bermuda to immediately terminate all active sessions, reset all credentials, upgrade to a supported firmware version as well s enable Multi-Factor Authentication, audit their configuratio and review logs for signs of compromise.

It said that if indicators of compromise are identified, including unrecognised accounts, unauthorised configuration changes or suspicious authentication activity, the affected device should be treated as compromised.

Leave a Reply

Your email address will not be published. Required fields are marked *