Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Data From 15,000 Fortinet Firewalls Leaked by Hackers

Hackers have leaked 15,000 Fortinet firewall configurations, which were apparently obtained as a result of exploitation of CVE-2022–40684.

Fortinet patches

A hacker group has leaked data associated with roughly 15,000 Fortinet firewalls and an analysis has shown that it was likely obtained back in 2022 through the exploitation of a vulnerability.

The hackers who leaked the data are calling themselves Belsen Group and they claim this is their “first official operation”. They announced on January 14 that the data is available for free, saying that it contains IPs, passwords and configurations associated with 15,000 Fortinet devices located around the world. 

Security researcher Kevin Beaumont has analyzed the leaked files and confirmed that the data is genuine after mapping it to internet-exposed Fortinet devices that are visible on the Shodan search engine.

The dumped data is classified based on country of origin, with each record containing an IP address, full configuration data, and plaintext credentials. The exposed information includes usernames, passwords, device management certificates, and firewall rules.

Based on the analysis of the leaked data and a device owned by one of the affected organizations, Beaumont determined that it was apparently collected in October 2022, likely through the exploitation of CVE-2022–40684.

The existence of CVE-2022–40684 came to light in October 2022, when Fortinet admitted that the zero-day had been exploited in at least one attack. 

Advertisement. Scroll to continue reading.

A few days after disclosure, a proof-of-concept (PoC) exploit was made public and exploitation started increasing. Fortinet at the time urged customers to take immediate action after seeing that many devices had remained unpatched.

Roughly a month and a half after CVE-2022–40684 was disclosed, a security firm warned that cybercriminals had been selling access to enterprise networks likely compromised through the exploitation of this vulnerability. 

Beaumont noted that the leaked files could still pose a risk to organizations as two-year-old data is “not very old” and “many of the devices are still online and reachable”. 

“Even if you patched back in 2022, you may still have been exploited as the configs were dumped years ago and only just released — you probably want to find out when you patched this vuln. Having a full device config including all firewall rules is… a lot of information,” the researcher advised Fortinet customers.

SecurityWeek has reached out to Fortinet for comment and will update this article if the company responds. 

The news comes shortly after Fortinet confirmed that a zero-day vulnerability tracked by the company as CVE-2024-55591 has been exploited in attacks, reportedly since at least November 2024. 

Related: Fortinet Patches Critical FortiWLM Vulnerability

Related: Fortinet VPN Zero-Day Exploited in Malware Attacks Remains Unpatched

Related: Citrix, Cisco, Fortinet Zero-Days Among 2023’s Most Exploited Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.