Hackers Leak Configs and VPN Credentials for 15,000 FortiGate Devices

A new hacking group, the “Belsen Group,” has leaked sensitive configuration files, IP addresses, and VPN credentials for over 15,000 FortiGate devices. The data was uploaded on the dark web to promote the group and includes files sorted by country and IP address. Each file contains sensitive information like firewall rules, private keys, and plain-text VPN passwords.

The leak is tied to the exploitation of the 2022 zero-day vulnerability CVE-2022–40684, which allowed hackers to download configurations and create rogue admin accounts. Although the data was collected in 2022, its exposure still poses risks if credentials and configurations haven’t been updated. Administrators are urged to change passwords and check for signs of compromise.

Source: BleepingComputer

Similar Posts