15K Fortinet Device Configs Leaked to the Dark Web
ID: d39e814f-d8d3-5ffe-bd06-69142c4bc466
STIX ID: report--d39e814f-d8d3-5ffe-bd06-69142c4bc466
Feed Name: Dark Reading
Threat Score
Fortinet device configurations and SSL‑VPN credentials for 15,474 devices were posted to the dark web by a group calling itself "Belsen Group", reportedly stolen via exploitation of CVE‑2022‑40684 (and earlier CVE‑2018‑13379). The dump includes IP addresses, admin usernames/passwords, device certificates, and firewall rules, which can reveal internal network structure and enable access if credentials remain valid; observers and Fortinet urge credential rotation and other mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
