Global maritime trade under threat from Fortibleed incident

Major maritime, ports and energy companies have been identified by Cydome’s threat-intelligence unit as having Fortinet Firewall passwords and logins leaked in the recent “FortiBleed” incident.
More than 86,000 Administrator credentials of Fortinet Firewalls and other devices protecting the networks of thousands of organisations across 194 countries were breached, with hackers gaining unauthorised access to the Fortinet devices and enabling them to further compromise the target networks and data.
Cydome research shows that the leak, which is estimated to represent 50% of all internet-reachable FortiGate devices, also included 703 satellite-linked IP addresses associated with maritime satcom service providers.

Of the 250+ maritime firms found to be impacted by the incident, most were shipowner/management companies, and “consistent with FortiBleed hitting the operational core of maritime trade, not just back-office IT,” said Cydome founder and CEO Nir Ayalon.
“Although we are still monitoring the extent of FortiBleed on the industry, of all maritime-related logins leaked, 41.5% were shipping and freight companies, 31.2% were offshore contractors and service companies, 10.7% newbuild and repair yards, and 6.7% were Port Authorities and logistics firms.
“The team found that 87% of Fortinet devices exposed to the internet still had internet-facing management interfaces available, while 63% of harvested credentials related to default or built-in administrator accounts that had never been renamed.
“This suggests that many organisations have not yet taken the steps needed to fully secure affected systems… probably because they don’t know they have been hacked, yet!” said Ayalon.
FortiBleed differs from many cyber incidents because it is not based on a newly discovered software vulnerability. Instead, it exploits older administrator credentials that remained vulnerable after software upgrades.
In many cases, organisations updated their systems but did not take all the necessary steps to fully replace and discard legacy passwords, allowing attackers to recover valid credentials and test them against live devices – even after the Fortinet software patch.
Commenting on the seriousness of the incident, Cydome co-founder and VP R&D Alon Ayalon said it has already prompted action from the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
“We urge organisations to follow the CISA guidance and terminate active administrator and VPN sessions, reset passwords, enable multi-factor authentication and investigate systems for signs of unauthorised access.”
Appearing in the FortiBleed dataset does not necessarily mean an organisation is compromised. “But it does indicate that credentials associated with its network security infrastructure have been exposed and should be treated as a potential vulnerability,” said the VP R&D.
“Shipping is one of the world’s most connected industries, and that connectivity is essential for efficient operations,” he said.
“If attackers obtain trusted administrator access, they can move through networks unnoticed, gain control over operational systems or sell the information to ransomware groups and other cybercriminals. Protecting digital identities is just as important as protecting the IT and OT systems themselves.”
Related News.
September 24, 2026
Cyprus Marine Club Welcomes a Full House for Aphentrica’s War Risks Presentation
The Cyprus Marine Club marked its return after the summer break with a full house at Gazebo Mare on Tuesday, 22 September, bringing together members,…
September 24, 2026
IMO seeks feedback on Maritime Single Window implementation
The International Maritime Organization (IMO) has launched a global survey to assess the implementation and use of Maritime Single Windows (MSWs),…
September 24, 2026
World Maritime Day industry panel to examine the gap between maritime policy and the reality of life at sea
OneCare Group will bring together crewing, safety, insurance and wellbeing specialists for a World Maritime Day webinar examining how shipping can…
September 24, 2026
IUMI President – Marine insurers are war insurers
Marine insurers are at the heart of managing war risks to global shipping and must continue to develop the tools needed to support and facilitate…
September 24, 2026
Seafarer welfare is improving amongst leading companies, but five years of evidence shows this progress is far from the norm
Five years on, the Seafarers’ Rights Code of Conduct is driving more than 1,000 companies to participate in RightShip’s Crew Welfare…
September 24, 2026
The UK ETS arrives for shipping what it means for charterers
Introduction The UK Emissions Trading Scheme (UK ETS) was extended to domestic maritime activity on 1 July 2026, following the EU ETS, FuelEU…
September 24, 2026
ABP Southampton invests locally with Marine Cranes to boost capability
Associated British Ports , the UK’s largest port operator, has invested a new marine deck crane aboard Spartina, one of the Port of Southampton’s…
September 24, 2026
BIMCO Shipping Number of the Week
Caribbean Basin crude oil and heavy product exports jump 45% “Seaborne exports of crude oil and heavy products from the Caribbean Basin have…
September 24, 2026
xclusiv S&P Report 21th September 2026
Pls find below the [xclusiv] S&P Report 21th September 2026 [xclusiv] 2026_09_21
September 24, 2026
Marine insurance supply remains stable as geopolitical and technical changes reshape the market, says IUMI President
The global marine insurance market remains in a stable position, with premium growth strongly supported by a weak USD in hull and cargo. Meanwhile…
Subscribe to our newsletter!
if you dont want to swim alone in the ocean of news, sign up for the newsletter, and you will receive daily all the important news of world shipping!
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved






















