Decision1 IT Solutions Ltd
Back to news
Cyber SecurityInfrastructure

The Fortinet Firewall Breach: Why Buying a Firewall Is Not Enough

Victoria Murgatroyd22 June 2026

Article

The Fortinet Firewall Breach: Why Buying a Firewall Is Not Enough

A recent 45-GPU supercomputer attack proved that buying an expensive firewall doesn't matter if your IT provider doesn't configure it correctly.

When news breaks about a massive global cybersecurity event, it is easy for local companies to assume they are too small to be targeted. But this week, as reports surfaced in Ars Technica about a severe breach involving Fortinet firewalls, many operations managers were left wondering if their own networks were silently exposed.

The reality is that hackers do not care where your business is located. They use automated tools to scan the entire internet for open doors. In this recent attack, cybercriminals successfully stole VPN credentials from thousands of sensitive corporate networks worldwide simply because the hardware was not configured correctly.

The Industrial Scale of Modern Cybercrime

To understand how advanced these threats have become, we only need to look at how this breach was executed. As detailed by The Register, the attackers did not rely on manual guessing. Instead, they utilized massive computing power to brute-force their way in.

As one security researcher noted on LinkedIn: "They intercept SSL VPN authentication, crack hashes on a 45-GPU cluster managed via Hashtopolis, and pivot into internal Active Directory environments. The operation processed 1.16 billion credential attempts against 320,777 FortiGate targets and 2.1 billion attempts against 163,650 MSSQL servers."

The Danger of Unconfigured Hardware

This industrial scale means that buying a high-end enterprise firewall is no longer enough to keep you safe. A firewall is just a tool. This massive breach occurred because businesses left specific administrative access points open to the public internet and failed to enforce Multi-Factor Authentication on their remote connections. Buying the lock does not work if no one remembers to turn the key.

How We Protect Our Clients

For the businesses we manage, this global threat was neutralized before it ever hit the headlines. Our approach relies on a strict, proactive framework rather than just installing a piece of hardware and walking away.

  1. Vector Closure: During onboarding, we explicitly disable the specific administrative interfaces that these hackers actively exploit.
  2. Strict Access Control: We drastically reduce your network's visibility to the open internet so your firewalls cannot even be found by these automated scanning techniques. Furthermore, we enforce multi-factor authentication on all remote access points. Even if a hacker managed to crack a staff password using a GPU cluster, they cannot bypass the secondary approval prompt.
  3. Proactive Patching: Our automated systems apply the required security patches released by the vendor long before a vulnerability reaches the mainstream news.

Is Your Network Actually Secured?

If you are unsure whether your current IT setup relies on just buying hardware or actually managing it actively, you can take a quick diagnostic. Use our free What IT Support Is Best for Us? tool to see exactly where your network stands today.

At Decision1, we help organisations secure their critical network borders and enforce strict access policies. If you'd like a review of your firewall and remote access setup, we can help. Contact us today.

Find us in Dunedin

Right in the heart of the city.

You'll find Decision1 IT Solutions in central Dunedin, supporting business and education clients across Otago, Central Otago, Southland and the rest of New Zealand through our IT Alliance partners.

Business name
Decision1 IT Solutions Ltd
Address
Dunedin, Otago, New Zealand
Phone
0800 471 823
03 471 8232
Hours
Mon – Fri · 8:30 am – 5:00 pm NZST
After-hours support available for Universal Support clients

Dunedin, Otago — proudly serving Aotearoa New Zealand.

Decision1 IT Solutions Ltd

Decision1 IT Solutions Ltd is a managed IT service provider (MSP) located in Dunedin, New Zealand. Services include Business Continuity, Cyber Security, Infrastructure, Communications and Productivity for small to medium businesses and the education sector.

IT, Done Right
Managed IT · Cyber Security · Cloud · Business Continuity
Follow us

Get in touch

Contact Us
IT services we provide: Managed IT services Dunedin · Cyber security Otago · Business continuity New Zealand · IT support Dunedin · Microsoft 365 Dunedin · Cloud migration Otago · Network infrastructure NZ · School IT services Otago · Healthcare IT Dunedin · Manufacturing IT support.
© 2026 Decision1 IT Solutions Ltd. All rights reserved.
Privacy PolicyDunedin · Otago · Aotearoa New Zealand