A massive credential-harvesting campaign has compromised more than thirty thousand Fortinet firewalls and VPN gateways across nearly two hundred countries, affecting government agencies, telecommunications companies, and other critical sectors. Security researchers from SOCRadar discovered the operation after finding an exposed server belonging to the attackers, who appear to be Russian-speaking and are using a fully automated system that continuously scans for vulnerable devices, tests stolen credentials, and uses compromised devices to harvest even more passwords. Organizations using Fortinet products are urged to immediately rotate all administrative credentials, enable multi-factor authentication, and review their authentication logs for suspicious activity.