By Adam Butler, Principal Cyber Solutions Architect

Just a few weeks ago, I wrote about a shift we’re seeing across the cyber security landscape. Attackers are increasingly targeting identity rather than infrastructure. Rather than breaking through security controls, they’re finding legitimate ways in through exposed credentials, weak enforcement and trusted access paths.

The recently discovered FortiBleed campaign is another reminder that this trend is accelerating.

A different kind of security incident

What makes FortiBleed notable isn’t a newly discovered software vulnerability or a critical patch that organisations have failed to apply.

Instead, it highlights a challenge many organisations continue to face: valid credentials falling into the wrong hands.

Researchers identified a large-scale campaign targeting internet-facing Fortinet firewalls and SSL VPN gateways, with tens of thousands of devices affected globally. According to reports, attackers were able to access systems using genuine credentials that had already been exposed through previous compromises and credential theft activity.

Whether those credentials were obtained recently or years ago is largely beside the point. If they still provide access, the risk remains real.

The problem isn’t password strength

One of the most interesting findings from the campaign is that many of the passwords involved weren’t weak.

In fact, they were often long, complex and compliant with traditional password policies.

The issue wasn’t that attackers guessed them. The issue was that they already knew them.

This highlights a reality many organisations are now facing. Password complexity remains important, but it can no longer be treated as a standalone security control. Once a credential has been exposed, its strength becomes largely irrelevant.

The conversation therefore needs to move beyond password policies alone and towards credential exposure, identity protection and continuous monitoring.

Identity has become the new attack surface

The wider lesson from FortiBleed extends beyond Fortinet devices.

Once attackers gained access, they were able to monitor VPN traffic, harvest additional credentials and move deeper into internal environments. In many cases, this activity occurred outside the visibility of traditional endpoint security tools.

This reflects a broader shift in attack methods. Rather than exploiting infrastructure vulnerabilities, attackers are increasingly exploiting trusted identities and accepted access paths. If an organisation cannot see where credentials are being used, exposed or abused, detecting that activity becomes significantly harder.

What organisations should do now

Guidance from cyber security authorities has been consistent:

  • Review and rotate administrative credentials
  • Enforce phishing-resistant multi-factor authentication (MFA)
  • Remove management interfaces from public internet exposure where possible
  • Monitor for credential exposure and suspicious authentication activity

These are important steps. However, organisations that respond most effectively to campaigns like FortiBleed typically do more than implement individual controls.

They prioritise visibility.

They understand where identities are exposed, how access is enforced and where attackers might be able to move if a credential is compromised.

That visibility often makes the difference between detecting suspicious activity early and discovering a compromise after the fact.

Security controls are only effective when they’re enforced

A key takeaway from FortiBleed is that many affected organisations would likely have appeared secure during a traditional point-in-time assessment.

The policies were in place. The passwords were strong. The controls existed.

But effective cyber resilience depends on more than simply having controls on paper. Organisations need confidence that those controls are consistently enforced, monitored and delivering the outcomes they were designed to achieve.

How ARO helps

At ARO, we help organisations move beyond compliance-driven security and towards measurable cyber resilience.

Our focus on understanding how security controls perform in the real world, identifying gaps in visibility, enforcement and response before attackers can exploit them.

Through our Cyber Maturity Assessments, Managed Detection and Response services, and identity-focused security strategies, we help organisations:

  • Understand their exposure to modern identity-based threats
  • Strengthen authentication and access controls
  • Improve visibility across cloud, endpoint and edge environments
  • Detect and respond to suspicious activity earlier
  • Reduce reliance on static credentials as a primary security control

FortiBleed is unlikely to be the last campaign built around exposed credentials.

The organisations that will be best placed to respond are those that assume exposure is possible and build the visibility, controls and resilience needed to manage it.

Because in today’s threat landscape, the question is no longer whether a password is strong enough.

It’s whether it should still be trusted at all.