- The attack on Fortinet firewalls: chronicle of an already known vulnerability
- Why Italian SMEs cannot ignore this warning
- The immediate impact on business operations
- What to do now: priority actions for Fortinet users
- The ongoing work: security as a process, not a product
- Outlook: cyber risk for SMEs in the 2027-2028 biennium
- How SHM Studio supports SMEs in digital risk management
In mid-June 2026, a group of Russian-speaking cybercriminals compromised tens of thousands of Fortinet firewalls and VPNs belonging to large companies worldwide. The technique used relies on already known credentials, meaning outdated or reused passwords. Therefore, the problem doesn't just affect large corporations: Italian SMEs using Fortinet devices are also exposed to real risks.
In fact, many small and medium-sized businesses entrust their perimeter security to Fortinet firewalls and VPNs without applying regular updates or credential rotation policies. Consequently, critical business infrastructure — data, management access, ERP systems — can become an accessible target. We at SHM Studio we constantly monitor the evolution of digital threats to support businesses in assessing technological risk.
In summary, this global attack is a clear wake-up call. SMEs need to act now: credential audits, firmware updates, and remote access policy reviews. SHM Studio can support companies in defining a secure digital strategy, integrating cybersecurity into the overall technological roadmap. Contacting us is the first step.
The attack on Fortinet firewalls: chronicle of an already known vulnerability
On June 17, 2026, TechCrunch has reported news of global significance. A group of Russian-speaking cybercriminals has allegedly compromised tens of thousands of Fortinet firewalls and VPNs. Targets include large companies distributed worldwide. However, the most concerning aspect isn't the scale of the attack: it's the method.
Criminals have exploited known credentials, meaning passwords previously exposed or never changed. This is not a sophisticated zero-day exploit. On the contrary, it's a basic technique applied on a large scale. This means the vulnerability doesn't lie in the Fortinet product itself, but in the credential management practices of system administrators.
Therefore, the risk perimeter expands enormously. It's not just multinationals with complex infrastructures that are at risk. Italian SMEs using Fortinet devices to protect their networks are also potentially exposed.
Why Italian SMEs cannot ignore this warning
Fortinet is one of the most popular network security vendors in the world. In Italy, Fortinet firewalls and VPNs are widely adopted by manufacturing companies, professional firms, retailers, and logistics businesses. Therefore, the installed base is significant even within the Italian production landscape.
The structural problem is well-known: SMEs often buy perimeter security devices and configure them only once. Afterward, they rarely update the firmware or rotate access credentials. This behavior creates a permanent vulnerability window. In fact, default credentials or those leaked in previous breaches are easily found on the dark web.
In addition, many Italian SMEs extended VPN access during and after the massive smart working phase of 2020-2022. As a result, there are now active remote accesses that are not monitored with due attention. Every unattended access is a potential entry point for an attacker.
According to the analyses of Gartner on cybersecurity , identity and access management remains one of the most overlooked critical points in medium-sized organizations. Similarly, the McKinsey Global Institute indicates that most successful attacks exploit already known vulnerabilities, not new exploits.
The immediate impact on business operations
A compromised firewall isn't just a technical issue. It's a direct threat to business continuity. Through unauthorized access to the perimeter network, an attacker can move laterally within the infrastructure. Then, they can reach ERP systems, customer databases, accounting archives, and internal communication tools.
In particular, for Italian SMEs active in B2B, a breach of this type can have serious consequences. Business customer data is often covered by confidentiality agreements. Therefore, an information leak can translate into reputational damage, loss of contracts, and potential GDPR sanctions.
Despite this, many companies underestimate the risk until they suffer a direct incident. This reactive approach is costly. According to industry estimates, the average cost of a data breach for a European SME exceeds €150,000, considering downtime, remediation, and business impact.
What to do now: priority actions for Fortinet users
Responding to this type of threat doesn't require extraordinary investments. It requires operational discipline and a methodical review of existing configurations. Below are the most urgent actions.
- Immediate credential audit: verify that no administrator account uses default passwords or credentials already exposed in previous breaches. Tools like HaveIBeenPwned can be a starting point.
- Firmware update: Fortinet regularly releases security patches. Check your installed version and apply available updates without delay.
- Review of active VPN accesses: disable all unnecessary VPN accounts. Every unused access is a residual risk.
- Enabling two-factor authentication (MFA): MFA drastically reduces the risk of unauthorized access even if credentials are compromised.
- Access log monitoring: implement an alerting system for anomalous access or repeated failed login attempts.
These measures do not replace a structured cybersecurity strategy. However, they represent the minimum acceptable level of protection for any SME handling sensitive data.
The ongoing work: security as a process, not a product
The most common mistake that we at SHM Studio we observe in Italian SMEs is treating cybersecurity as a one-time purchase. You buy the firewall, install it, and forget about it. On the contrary, security is a continuous process that requires periodic reviews, constant updates, and staff training.
In this context, the AI-driven digital transformation introduces new attack surfaces. Every new digital tool adopted — whether it's a cloud CRM, an API integration, or an automation system — expands the perimeter to be protected. Therefore, security must be integrated into the digital strategy from the design phase.
For SMEs that are investing in web presence and Digital marketing , it is essential that the underlying technological infrastructure is solid. A company website or a campaign Google Ads conversion that works well is worthless if internal systems are vulnerable to a breach.
Outlook: cyber risk for SMEs in the 2027-2028 biennium
The projections for the next two years are not reassuring. The attack surface for SMEs will continue to expand. In fact, the growing adoption of SaaS tools, integration with e-commerce platforms, and the use of generative AI for internal processes multiply the potential access points.
Furthermore, cybercriminal groups are becoming more organized and more efficient. As highlighted by Wired Security , the professionalization of cybercrime has lowered the technical threshold needed to conduct large-scale attacks. As a result, even SMEs—historically considered less attractive targets—are now in the crosshairs.
For this reason, investing in security skills and processes is no longer an option reserved for large corporations. It's a competitive necessity for any company that wants to operate reliably in the digital market.
How SHM Studio supports SMEs in digital risk management
We at SHM Studio we support Italian SMEs in building solid and secure digital infrastructures. Our approach integrates the security dimension into every phase of the digital project: from web design to the definition of SEO strategies , from the LinkedIn campaigns to the production of editorial content .
We don't offer operational cybersecurity services in the strict sense. However, we can support companies in assessing technological risk and identifying the most suitable specialized partners for their needs. Therefore, our role is that of all-around digital consultants, capable of understanding the security implications in everyday technological choices.
SMEs interested in assessing their digital maturity can contact us for an initial comparison. Explore the our blog it's also a good starting point for catching up on industry trends.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.