Data Breaches

Fortinet Data Breach Impacts Customer Information

Fortinet has confirmed suffering a data breach impacting customers after a hacker leaked files allegedly stolen from the company.

Fortinet vulnerability

Fortinet on Thursday confirmed suffering a data breach impacting customers after a hacker leaked files allegedly belonging to the cybersecurity company.

The hacker, who uses the online moniker ‘Fortibitch’, made the announcement on a popular hacking forum and claimed that the data — 440 Gb in total — came from an Azure Sharepoint instance. 

The threat actor indicated that the decision to make the stolen data available came after Fortinet refused to pay a ransom.

The hacker has shared information for accessing an AWS S3 bucket that allegedly stores the data, but SecurityWeek has not attempted to access it. Several users of the hacker forum complained about not being able to gain access to the files. 

Shortly after the hacker posted the information for obtaining the data, Fortinet issued a security incident notice, confirming that “an individual gained unauthorized access to a limited number of files stored on Fortinet’s instance of a third-party cloud-based shared file drive”.

The cybersecurity giant said the compromised data included limited information related to less than 0.3% of its customers.

Advertisement. Scroll to continue reading.

Fortinet clarified that its operations, products and services have not been affected, and there is no evidence of unauthorized access to other resources.

While the hacker attempted to get a ransom payment, the incident did not involve data encryption, ransomware deployment, or access to the company’s corporate network, Fortinet said.

“To-date there is no indication that this incident has resulted in malicious activity affecting any customers,” Fortinet noted, adding, “Given the limited nature of the incident, we have not experienced, and do not currently believe that the incident is reasonably likely to have, a material impact to our financial condition or operating results.”

Fortinet said the results of its own investigation have been validated by outside forensics experts. The company has notified law enforcement and some cybersecurity agencies.

Related: Fortinet, Zoom Patch Multiple Vulnerabilities

Related: Fortinet Patches Code Execution Vulnerability in FortiOS

Related: Fortinet Expands Cloud Security Portfolio with Lacework Acquisition

Related Content

Network Security

A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign.

Data Breaches

HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers.

Data Breaches

Hackers stole personal information after breaching the systems of a third-party license vendor serving TPWD.

Malware & Threats

The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs.

Data Breaches

Kodak told SecurityWeek it believes there is no threat to its systems or operations as a result of the cybersecurity incident.

Vulnerabilities

SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking. 

Data Breaches

The digital health company said it learned of the breach on June 8 and the attackers demanded a ransom.

Data Breaches

The hack-and-leak group FulcrumSec claims to have stolen 1.3TB of data from the pharmaceutical giant.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version