Fortinet leaked passwords, stole secret Turkish defense documents

If you have a Fortinet firewall, stop what you're doing and change your passwords. Attackers somehow gained access to about 75.000 Fortinet firewall devices and stole credentials belonging to major companies in 194 countries.

Security researchers report that they have verified the data and the compromised FortiGate passwords belong to accounts spanning multinational companies, including FoxConn, Samsung, Comcast, Siemens, Lenovo, FedEx, PxW, Accenture, Oracle, and many others.

See more articles from iGuRu.gr when you search for news on Google.

Check if your organization is included in the list of affected domains – and immediately change all passwords associated with your VPN and Fortinet management interfaces.

Make sure multi-factor authentication is enabled as well, as this type of mass credential leak can lead to very serious situations, giving attackers full, remote access not only to the firewall but also to the entire corporate network.

Hudson Rock, who analyzed the data, said the leak affects 21.632 unique domains.

"The scale of this breach touches nearly every sector of the global economy, not excluding industry. The attackers created a verified database of operational credentials for some of the largest businesses on the planet," he wrote on the Infostealer blog.

Researcher Volodymyr “Bob” Diachenko first identified the intrusions and attributed them to a Russian-speaking group.

“They intercept SSL VPN authentication, crack hashes on a 45 GPU cluster managed through Hashtopolis, and migrate to internal Active Directory environments,” he wrote on LinkedIn. “The enterprise processed 1,16 billion credential attempts against 320.777 FortiGate targets and 2,1 billion attempts against 163.650 MSSQL servers.”

Furthermore, according to Diachenko, the criminals completely took over at least four organizations, including a Turkish NATO defense contractor, and in this case, stole classified defense documents.

Security researcher Kevin Beaumont, who also verified the stolen credentials, reported

“I have worked with several organizations listed and can confirm that the login names and passwords are real.”


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).