logo

15K Fortigate Firewall Configs Leaked By Belsen Group: Dumped Using Zero-Day in 2022

ID: d1f0b310-1b71-573f-a587-84cb004529a8

STIX ID: report--d1f0b310-1b71-573f-a587-84cb004529a8

Feed Name: CloudSEK Blog

Threat Score
80/100

Date Published: 2025-01-16

Date Updated: 2026-04-27

...
...

This report describes a large-scale leak of over 15,000 FortiGate firewall configurations allegedly published by the Belsen Group; the leak is linked to mass exploitation of an authentication-bypass zero-day (CVE-2022-40684) in 2022 and includes exposed credentials, firewall rules, and device certificates, with an associated pastebin of affected IPs and recommended mitigations (credential changes, certificate rotation, firewall audits, and forensic investigation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.