Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Hackers selling UK government login credentials on dark web amid FortiBleed campaign

The FortiBleed campaign targets internet-facing Fortinet VPNs and firewalls, harvesting credentials via automated tools, which are then sold on the dark web. The exposed data includes privileged credentials, posing a significant risk to core government and corporate networks. Fortinet has stated this is likely a reshare of data from previous incidents or brute-forced credentials, not a new breach.
Read Full Article →

Identity Hackers selling UK government login credentials on dark web amid FortiBleed campaign July 9, 2026 Share By SC Staff Cybersecurity experts have issued an alert following reports that hackers accessed login credentials belonging to UK government officials and Foreign Office staff. The credentials, reportedly being sold on the dark web, were exposed as part of the ongoing FortiBleed attack campaign, according to a recent report by IT Pro. The FortiBleed campaign targets internet-facing Fortinet VPNs and firewalls, with over 70,000 devices in 194 countries believed to be affected. Analysis by SOCRadar identified a database containing login credentials, attributed to the Lynx/INC ransomware group. While initially thought to be basic usernames and passwords, reports suggest some exposed details include privileged Fortinet credentials. These could grant attackers access to core government networks, including the Foreign Office, NHS trusts, energy companies, and local councils. Some Foreign Office credentials are being sold for up to £40,000 on the dark web. Security researchers warn this sophisticated credential harvesting operation, using automated tools at high speed and volume, exponentially increases the risk to all organizations, not just government entities. Fortinet has stated the exposed data is likely a reshare from previous incidents or brute-forced credentials, not a result of a new breach. Source: IT Pro SC Staff Related Identity Seeing the unseen: Closing AI identity blind spots Paul Wagenseil July 8, 2026 Here's how ISPM provides the necessary visibility, governance and risk assessment to manage AI agents. Privacy Sainsbury’s expands facial recognition use to combat shoplifting SC Staff July 6, 2026 The supermarket chain is tripling the number of stores utilizing facial recognition, expanding from over 55 current locations to a projected 200 by year-end. Identity Massive password spray attack targets Azure CLI, bypasses MFA SC Staff July 2, 2026 The attack, which leveraged a deprecated OAuth flow called Resource Owner Password Credentials (ROPC), made over 81 million login attempts between June 12 and June 26, compromising at least 78 Microsoft accounts across 64 organizations. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds

Share this article