logo

15K Fortinet Device Configs Leaked to the Dark Web

ID: d39e814f-d8d3-5ffe-bd06-69142c4bc466

STIX ID: report--d39e814f-d8d3-5ffe-bd06-69142c4bc466

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-01-17

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Fortinet device configurations and SSL‑VPN credentials for 15,474 devices were posted to the dark web by a group calling itself "Belsen Group", reportedly stolen via exploitation of CVE‑2022‑40684 (and earlier CVE‑2018‑13379). The dump includes IP addresses, admin usernames/passwords, device certificates, and firewall rules, which can reveal internal network structure and enable access if credentials remain valid; observers and Fortinet urge credential rotation and other mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.