Fortinet Confirms Customer Data Breach via Third Party
ID: 5f674096-533b-5741-a7c5-a461631b4b48
STIX ID: report--5f674096-533b-5741-a7c5-a461631b4b48
Feed Name: Dark Reading
Fortinet confirmed an unauthorized access incident in which a threat actor allegedly exfiltrated and leaked ~440 GB of files from a third-party cloud-based SharePoint instance, impacting under 0.3% of its ~775,000 customers (~2,325 organizations). The actor posted the data on BreachForums after an apparent failed extortion attempt; leaked content reportedly includes customer information, financial and marketing documents, product materials, and HR/employee data. Fortinet says there is no evidence of ransomware deployment or compromise of its corporate network; investigators suggest likely vectors include credential compromise (phishing) or information-stealer malware and emphasize the need for stronger SaaS guardrails such as MFA, encryption, and continuous monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
