logo

FortiGate config leaks: Victims' email addresses published online

ID: 546db18d-a3ba-5d78-ba01-9f9f0e05fd9d

STIX ID: report--546db18d-a3ba-5d78-ba01-9f9f0e05fd9d

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2025-01-23

Date Updated: 2026-04-26

Author: Connor Jones

...
...

The Belsen Group has published ~15,000 FortiGate configuration files stolen during the 2022 exploitation of CVE-2022-40684, exposing thousands of IPs and email addresses, some plaintext credentials, and about 12,000 IPsec VPN tunnel configurations; researchers published extracted emails and IPs to help defenders, while Fortinet confirmed the leak and urged remediation and compromise assessments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.