Nam entities warned of Fortinet cyber breach
Namibian businesses and organisations have been warned that cyber security is not a once-off compliance exercise but a constant operational discipline. This is after the country’s cyber security incident response team, NAM-CSIRT, flagged a global incident exposing sensitive access to data on internet-facing Fortinet FortiGate devices. In a statement issued on Saturday, the Namibia Cyber... The post Nam entities warned of Fortinet cyber breach appeared first on New Era .

AI summary
Namibian businesses and organisations have been warned that cyber security is not a once-off compliance exercise but a constant operational discipline. This is after the country’s cyber security incident response team, NAM-CSIRT, flagged a global incident exposing sensitive access to data on internet-facing Fortinet FortiGate devices.
In a statement issued on Saturday, the Namibia Cyber Security Incident Response Team, housed at the Communications Regulatory Authority of Namibia (CRAN), noted that the incident, dubbed FortiBleed, involves the exposure of administrator credentials, VPN credentials and firewall configuration data. For businesses relying on Fortinet infrastructure, that creates a dangerous opening that attackers could slip into corporate networks posing as legitimate users, quietly change security settings, steal sensitive data or pave the way for ransomware attacks.
The warning lands close to home and the NAM-CSIRT has identified 13 Namibian organisations whose systems may have been exposed and has already contacted them with urgent remediation guidance. While there is no evidence yet of widespread compromise, the alert underscores a blunt reality for executives and IT teams alike, that a network can appear stable even while its digital front gate has effectively been left unlocked.
That is what makes incidents like FortiBleed so disruptive because Firewalls and VPNs are meant to be the first line of defence, but when their credentials are exposed, they can become a liability instead of a safeguard. The risk is not only technical, as a breach of this kind can trigger operational downtime, regulatory scrutiny, reputational damage and direct financial losses.
CRAN’s message is that continuous vigilance matters more than reactive clean-up. The authority’s recommended actions include rotating administrator and VPN credentials, enabling multi-factor authentication, upgrading Fortinet devices, restricting public access to management interfaces, reviewing configurations for tampering, and intensifying log reviews and threat hunting – are standard controls, but in this case they are also urgent business imperatives.
Mufaro Nesongano, CRAN’s Executive for Communication and Consumer Relations, said the incident should be seen as a broader wake-up call that cyber threats are evolving constantly, and preparedness remains the strongest defence.
“While there is currently no evidence of widespread compromise among affected Namibian organisations, this incident highlights the importance of proactive cyber security measures. We commend the organisations that have acted swiftly to implement the recommended remediation steps and encourage all entities using internet-facing infrastructure to regularly review their security posture. Cyber threats continue to evolve, and preparedness remains our strongest defence,” Nesongano stated.
For Namibia’s corporate sector, the lesson is that cyber resilience depends less on whether an organisation has security tools in place and more on whether it is actively maintaining, auditing and challenging those defences every day.
The post Nam entities warned of Fortinet cyber breach appeared first on New Era.
Follow the story
About this article
- Length
- 456 words · 2 min read
- Published
- June 22, 2026
- Byline
- Edgar Brandt
- Source
- New Era Namibia