Back to home
Business·

Andorra Warns of FortiBleed Cyber Campaign Targeting Local Fortinet Systems

Andorra's cybersecurity agency identified local systems in a massive FortiBleed espionage operation using infostealer malware credentials. Affected entities notified; monitoring continues amid global hits on critical sectors.

Key Points

  • ANC-AD confirms Andorran FortiGate firewalls among 73,900 targeted in 194 countries via 1.16B login attempts.
  • Two parishes and a tax firm potentially exposed with stolen VPN credentials; no breaches confirmed.
  • 10 Andorran IPs likely compromised, probable Russian-speaking attackers.
  • Agency urges credential resets, MFA activation, log reviews, and vulnerability checks.

Andorra's National Cybersecurity Agency (ANC-AD) has warned of the "FortiBleed" cyber-espionage campaign, confirming Andorran Fortinet systems among more than 73,900 firewalls targeted across 194 countries through over 1.16 billion login attempts using stolen credentials from infostealer malware.

The agency has notified affected companies and institutions via standard channels after verifying local FortiGate firewalls, FortiOS platforms, and SSL VPN gateways in the attackers' victim database. No effective breaches have been confirmed in Andorra, though the ANC-AD continues to assess the full scope and monitor for impacts on national businesses.

Álvaro Martínez, president of the Electronic Frontier Protection Association, specified that two parishes and a tax advisory firm are among those potentially exposed. Cybercriminals possess VPN access credentials for these entities, he said, which could allow them to pose as legitimate staff and reach internal files or sensitive information without detection. "We know they have the credentials, but we don't know if they've entered and used them," Martínez noted. For one parish, attackers obtained both VPN access and credentials, while the other had only VPN access. He identified 10 Andorran IP addresses as likely compromised and pointed to probable Russian-speaking perpetrators.

The global operation has struck critical sectors including governments, defence, telecoms, finance, healthcare, and key infrastructure. Martínez stressed separating confirmed facts from potential risks, urging investigations into intrusions, credential revocations, generation of secure new logins, and data leak audits if compromises are proven.

The ANC-AD advises Fortinet users to consult suppliers and maintenance services for vulnerability checks, promptly reset all corporate credentials and VPN/admin passwords, activate multi-factor authentication, scrutinise access logs for suspicious activity such as logins from odd locations, unauthorised admin sessions, or abnormal traffic, and shield admin interfaces from public exposure.

Share the article via