Back to knowledge baseNEWS

The password on thousands of firewalls was simply “admin”

Elli31 August 20264 min read

Earlier this year, attackers found a flaw in software made by Fortinet, one of the world's largest firewall vendors. The result: hackers walked straight into more than 270 Belgian businesses and organisations. Not through some clever trick, but through a front door nobody had bothered to lock.

What's going on

The vulnerability, now known as “FortiBleed”, sat in Fortinet firewalls — the devices meant to shield a company's network from the outside world. A Russian hacking collective used it systematically to break into IT providers that manage firewalls on behalf of their clients, gaining indirect access to those clients' networks in turn. According to Belgian broadcaster VRT NWS, the attack touched companies across Fortinet's global customer base, with at least 270 Belgian organisations affected.

What stands out most is how simple the underlying mistake was for many victims. More than 1,300 firewalls worldwide were found with “admin” as both username and password — a factory default that was never changed after installation.

“That simply cannot happen.” — Geert Baudewijns, CEO of cybersecurity firm Secutec, to VRT NWS.

At the time of reporting, more than 100 Belgian organisations still had a firewall with visible login credentials exposed online, and attackers had already actively created new accounts on at least 45 Belgian systems. The affected sectors are no coincidence: transport companies, law firms, school groups, and local government bodies — organisations that typically don't have a large IT team keeping constant watch over what's visible from the outside.

This fits a wider pattern. The Centre for Cybersecurity Belgium (CCB) recorded a 58% rise in reported cyber incidents in 2025 compared to the year before, with break-ins via stolen or guessed login credentials as the single largest category. Even more telling: the average gap between a vulnerability becoming public and the first active attacks has shrunk to roughly five days — and nearly a third of vulnerabilities are exploited within 24 hours of disclosure. Waiting to patch, or putting off changing a password until “later”, is no longer a workable plan.

Why this affects SMEs

A firewall or a remote-access device is usually installed once, by an IT provider, and then forgotten. Nobody is specifically tasked with checking, months or years later, whether it's still up to date, or whether that default password was ever changed. A larger company often has its own IT or security team doing exactly that kind of check. An SME rarely does — and that's exactly why the victim list for this attack reads like transport firms and law offices rather than only multinationals.

On top of that, an SME often has no clear picture of what it actually exposes to the outside world: which devices are reachable online, which ports are open, which software has fallen behind on updates. An attacker does have that picture — they scan the internet continuously for exactly this kind of weak spot. That gap, between what a business thinks it's showing the world and what an outsider can actually see, is usually where things go wrong.

What to actually do about it

  • Change every default password on firewalls, routers, and remote-access devices. “admin/admin” or any other factory setting is the first thing an attacker tries.
  • Ask the IT provider directly: are all firewalls and internet-facing devices running the latest version, and is there a fixed schedule for when updates happen?
  • Turn on multi-factor authentication (MFA) for any form of remote administration — a second check beyond the password, such as a code on a phone.
  • Have what's visible from the outside checked regularly. The same outside view an attacker uses to scan for an open door can be used first, to close it.
  • Make patching a routine, not a once-a-year task. With an average of five days between a known vulnerability and the first attack, “sometime soon” is already too late.

How NetGuard helps

Exactly this kind of situation — a device installed years ago and never looked at since — is where External Attack Surface Management (EASM, the ongoing practice of mapping what an outsider can see of a business online) makes the difference. Rather than waiting for an attacker to find an open firewall or an outdated system, EASM brings that same outside view to the business itself, so a default password or a missed update gets noticed before someone else finds it. A no-obligation introduction can be arranged by e-mail.

Share this article

Elli

No author profile available.

Related articles

News

That voice on the phone might not be human

Scammers now use AI to mimic the voice of a business owner to push through an urgent payment. Here's how this new form of CEO fraud works, and five concrete steps to reduce the risk.

13 August 20265 min read
The password on thousands of firewalls was simply “admin” | NetGuard