Shipyards among firms exposed in FortiBleed credential leak

Some 10.7% of leaked logins were linked with shipyards, Cydome found (Source: Cydome)
Newbuild and shiprepair yards account for one in ten maritime organisations identified in the FortiBleed credential exposure incident, according to cybersecurity specialist Cydome, highlighting the potential vulnerability of shipyard networks that increasingly rely on connected digital systems.
The company said analysis of the leaked dataset found more than 250 maritime organisations potentially affected. Of all maritime-related logins identified, 10.7% were linked to shipyards, while shipping and freight companies accounted for 41.5% and offshore contractors and service companies represented 31.2%.
Cydome estimated that the leak affected credentials associated with around half of all internet-reachable FortiGate devices globally. The exposed data also included 703 satellite-linked IP addresses connected to maritime communications providers.
According to Cydome, the incident is particularly significant because it affects organisations operating critical industrial environments and operational technology (OT) rather than purely administrative networks. Founder and chief executive Nir Ayalon said the findings were “consistent with FortiBleed hitting the operational core of maritime trade, not just back-office IT”.
The company reported that 87% of internet-exposed Fortinet devices identified in the dataset still had management interfaces accessible online, while 63% of harvested credentials were associated with default or built-in administrator accounts that had never been renamed.
Unlike many recent cyber incidents, FortiBleed does not rely on a newly discovered software vulnerability. Instead, attackers exploit legacy administrator credentials that remained usable after software updates. As a result, organisations that installed security patches may still be vulnerable if old credentials were not fully replaced.
For shipyards, where production planning, welding automation, asset management, inspection systems and other operational technologies are increasingly integrated with corporate networks, unauthorised administrator access could create risks extending beyond office systems.
Cydome urged organisations to follow guidance issued by the US Cybersecurity and Infrastructure Security Agency, including resetting passwords, enabling multi-factor authentication and investigating networks for signs of unauthorised access.