An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a
https://duo.com/decipher/hive-ransomware-attacks-target-fortios-microsoft-exchange-flaws
https://www.tenable.com/cyber-exposure/a-look-inside-the-ransomware-ecosystem
https://www.tenable.com/cyber-exposure/2021-threat-landscape-retrospective
https://www.tenable.com/blog/hold-the-door-why-organizations-need-to-prioritize-patching-ssl-vpns
https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a