Nigerian organisations have been placed on high alert following the emergence of a massive global cyberattack campaign targeting Fortinet firewall and virtual private network (VPN) devices, raising fears of data theft, ransomware attacks and widespread network compromise.
In a security advisory issued by CERRT.NG, the agency warned that the campaign, dubbed FortiBleed, has already affected thousands of internet-facing Fortinet devices worldwide, exposing organisations to potentially devastating cyber intrusions.
According to the advisory, cybercriminals are exploiting exposed, weak or previously leaked credentials to gain unauthorized access to Fortinet FortiGate firewalls and SSL VPN appliances, which serve as critical gateways protecting corporate and government networks.
Security experts warned that once attackers gain access to these systems, they can effectively obtain the keys to an organisation’s digital infrastructure.
“The compromise of these devices can facilitate malware deployment, ransomware attacks, data exfiltration and broader organisational breaches,” the advisory stated.
The alert specifically affects internet-facing Fortinet management interfaces, FortiGate firewalls and SSL VPN appliances that are accessible from the public internet.
Cybersecurity analysts say the scale of the operation has sent shockwaves through the global security community because compromised firewalls often provide attackers with deep visibility into network traffic, user activities and connected systems.
A successful breach could allow threat actors to steal sensitive information, harvest user credentials, establish persistent access to networks and move laterally across systems undetected, potentially crippling critical operations.
The advisory comes amid growing concerns over the increasing sophistication of cybercriminal groups targeting network infrastructure rather than individual endpoints, a tactic that allows attackers to infiltrate entire organisations through a single compromised device.
To prevent potential compromise, CERRT.NG urged organisations using Fortinet products to immediately reset and rotate all administrative and VPN credentials, particularly passwords that may have been reused or previously exposed in data breaches.
The agency also advised organisations to enforce multi-factor authentication (MFA) for all administrative and remote-access accounts, remove or restrict direct internet access to management interfaces, and closely review firewall and authentication logs for suspicious activities.
In addition, organisations were urged to ensure that all Fortinet devices are updated with the latest supported firmware and security patches released by the vendor.
The warning underscores the growing cyber threat landscape facing businesses, government agencies and critical infrastructure operators, as attackers increasingly exploit weak security practices to gain access to high-value systems.
With Fortinet devices widely deployed across financial institutions, government establishments, telecommunications firms and private enterprises, cybersecurity experts say swift action is crucial to prevent local networks from becoming the next victims of the expanding FortiBleed campaign.