About Platform Resources Articles Contact
AI & Security  ·  IMA AI

The Firewall Company Got Breached.
You Are Not Too Small to Be Next.

A friend of mine works at Fortinet — a company you buy security from. Around 75,000 of its firewalls and VPNs were just breached. If the wall itself can be climbed, the comforting story Malaysian businesses tell themselves — "we're too small for anyone to bother" — is finished. And AI just finished it.

Published  July 2026
By  Chin Qi Yong, CEO — IMA AI
© 2026 Chin Qi Yong
Read time  ~6 min

A friend at the firewall company

A friend of mine works at Fortinet. If you don't know the name, it's one of the companies the rest of the world buys its security from — firewalls and VPNs sitting at the front door of banks, factories, and governments.

In June, roughly 75,000 of those Fortinet devices were compromised in a campaign now called FortiBleed — across more than fifteen countries, hitting Fortune 500 names and government agencies alike. Read that slowly: the company that sells the wall had 75,000 of its walls climbed.

The uncomfortable detail
Fortinet says this wasn't some exotic new flaw. It was reused and guessed passwords, cracked at scale by a cluster of machines built for nothing but breaking VPN logins. The lock was fine. The keys were lying around.

The story Malaysian businesses tell themselves

Here's what I hear from owners at home, again and again: "Nobody's going to attack us. We're too small. Hackers go after the giants."

I understand where it comes from, but it was always half true and it's now dangerous. A friend inside the security industry tells me what the numbers already suggest — that Malaysian firms, across the board, spend well below global benchmarks on security. Not because owners are careless, but because it feels like insurance against a fire that only happens to other people.

That belief had one load-bearing assumption: that attacking a small business costs the attacker more time than it's worth. Break that assumption and the whole thing collapses.

AI just broke the assumption

In September 2025, Anthropic disclosed something that should have been front-page news in every boardroom: it disrupted the first documented large-scale cyberattack run mostly by AI. A group pointed an AI coding agent at around thirty targets — tech firms, banks, chemical makers, government bodies — and the AI carried out an estimated 80 to 90 percent of the actual attack on its own, at a speed no human team could match.

Sit with what that means for the "too small" excuse. Attacks used to require a skilled, expensive team, so attackers rationed their effort and aimed at big prizes. When the machine does most of the work, that math flips. The cost of attacking a small target falls toward zero — and anything that costs nothing gets done to everyone. You don't need a giant to be worth robbing; you just need to be reachable and unlocked.

The person aiming the tool no longer has to be a genius. That is the part owners haven't absorbed.

It's already happening here

This isn't a foreign problem I'm importing to scare you. Look at the Selangor parking app.

In late June, Flexi Parking — the payment app used across dozens of Selangor councils — was breached, with the attackers claiming millions of user records and councils forced to pause enforcement. The break-in used two of the oldest, most preventable mistakes in the book, on a server reportedly still running a software core from 2021. This wasn't a state-of-the-art assault. It was an unlocked door on a system tied to a state government.

If that's the security posture on a public-facing app connected to a state, ask yourself honestly what the posture looks like at the average Malaysian SME.

I don't blame the businesses. I blame the floor.

And here's where I'll be direct: I don't mainly fault the owners. I fault the fact that we spent years loudly promoting "digital transformation" without ever building the floor underneath it.

Yes, we now have a Cyber Security Act on the books. But a law on paper is not an enforced baseline. A council-linked app running a four-year-old core with beginner-level holes tells you exactly how far the paper is from the practice. We are a country that is still arguing about whether petrol stations should accept digital payment — and in the same breath we tell small businesses to move their entire livelihood online.

You cannot push everyone into the water and then act surprised that nobody was taught to swim. Transformation without a security baseline isn't progress. It's exposure with better marketing.

Even the leader is not safe

There's a last lesson hiding in the Fortinet story, and it's the one I keep coming back to. Fortinet is a world leader. It still got breached at a scale of 75,000 devices. Being number one today guarantees nothing about tomorrow — I've watched that movie before, and it was called Nokia.

The same reset that is coming for every incumbent is coming for the security incumbents too. Nobody gets to coast on the reputation they earned in the old world — not the vendors, not the banks, and not us.

What I'd want

For businesses: drop the "too small" story and do the unglamorous basics — real passwords, updates, someone accountable for it. It is far cheaper than the day you find out you were reachable and unlocked.

For those who run the country: an enforced security floor for the systems ordinary people are told to trust, not another launch event. The generation holding the levers has to treat digital risk as real and urgent — the way the threat already does.

The attackers have already upgraded their tools. The only question is whether we upgrade our assumptions before, or after, it's our turn.

Now or Never.

CQ
Chin Qi Yong
CEO, IMA AI
Chin Qi Yong is the CEO of IMA AI — building the infrastructure layer for agent-era commerce and identity in Malaysia. IMA AI's products are designed for the world where AI agents transact, verify, and operate on behalf of humans.
Follow on LinkedIn

Published by IMA AI — July 2026.