• News/
  • https://www.theregister.com/2025/01/23/fortigate_config_leaks_infoseccers_list_victim_emails/

FortiGate config leaks: Victims' email addresses published

The Register
·
Connor Jones
·
Published Jan 23, 2025
·
Updated

Thousands of email addresses included in the Belsen Group's dump of FortiGate configs last week are now available online, revealing which organizations may have been impacted by the 2022 zero-day exploits. Infosec expert Kevin Beaumont uploaded the IP and email addresses associated with the leaked FortiGate configs to GitHub, while fellow researcher Florian Roth separately extracted them and grouped them via top-level domains (TLDs). Beaumont said the aim here was to provide defenders with the information they need to identify which organizations may have been impacted and require further investigation. However, not everyone will include their email addresses in config files, so the resource won't help every victim. According to Roth's grouped data, a smidge under 5,000 organizations' domains were included, and may benefit from, Beaumont's publication. However, onlookers in the security community, such as one Group-IB threat intelligence analyst, said the list isn't exhaustive and doesn't capture all the emails included in the leak. The victim list that was published is truly global, however. A few simple CTRL+Fs reveal a selection of major, high-profile organizations are included, as well as a bevy of domains tied to governments around the world. The Register contacted some of the more notable inclusions in the data for a response. A reminder for those who missed last week's leak: A new band of baddies going by the name of The Belsen Group leaked around 15,000 FortiGate conf...

Read full article

Affected Software

2 affected components
Fortinet FortiGate
Fortinet FortiGate
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the leak of FortiGate configuration files that exposed thousands of victims' email addresses.

2

What security implications are discussed?

The leaked configurations provide insights into organizations affected by past zero-day exploits, increasing the risk of targeted attacks.

3

What products or software are affected?

The affected software mentioned in the article is Fortinet's FortiGate.

4

Who released the leaked information?

The Belsen Group is responsible for releasing the leaked FortiGate configuration files.

5

What year did the relevant zero-day exploits occur?

The zero-day exploits that the article references occurred in 2022.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203