A new hacking group has leaked the configuration files, IP addresses, and VPN credentials for over 15,000 FortiGate devices for free on the dark web, exposing a great deal of sensitive technical information to other cybercriminals. The data was leaked by the "Belsen Group," a new hacking group first appearing on social media and cybercrime forums this month. To promote themselves, the Belsen Group has created a Tor website where they released the FortiGate data dump for free to be used by other threat actors. "At the beginning of the year, and as a positive start for us, and in order to solidify the name of our group in your memory, we are proud to announce our first official operation: Will be published of sensitive data from over 15,000 targets worldwide (both governmental and private sectors) that have been hacked and their data extracted," reads a hacking forum post. The FortiGate leak consists of a 1.6 GB archive containing folders ordered by country. Each folder contains further subfolders for each FortiGate's IP address in that country. According to cybersecurity expert Kevin Beaumont, each IP address has a configuration.conf (Fortigate config dump) and a vpn-passwords.txt file, with some of the passwords in plain text. The configs also contain sensitive information, such as private keys and firewall rules. In a blog post about the FortiGate leak, Beaumont says that the leak is believed to be linked to a 2022 zero-day tracked as CVE-2022–40684 that was exploited in at...
Hackers leak configs and VPN credentials for 15,000 FortiGate devices
BleepingComputer
·Lawrence Abrams
·Published Jan 16, 2025
·Updated
Affected Software
11 affected components
Fortinet FortiGate=7.0.0
Fortinet FortiGate=7.0.1
Fortinet FortiGate=7.0.2
Fortinet FortiGate=7.0.3
Fortinet FortiGate=7.0.4
Fortinet FortiGate=7.0.5
Fortinet FortiGate=7.0.6
Fortinet FortiGate=7.2.0
Fortinet FortiGate=7.2.1
Fortinet FortiGate=7.2.2
Fortinet FortiGate