Massive Breach Exposes Credentials for Sensitive Networks

A significant security breach has compromised thousands of Fortinet firewalls, exposing sensitive credentials for major organizations worldwide.

3 min readCybersecurity

A recent security incident has revealed that numerous Fortinet firewalls have been breached, allowing Russian-speaking cybercriminals to gain extensive access to major global entities, including Oracle, Chevron, Lenovo, and Federal Express, among others. According to Bob Diachenko, a security researcher, nearly 74,000 devices across over 21,000 IP addresses in 194 nations have had their plaintext credentials leaked online. Diachenko discovered this data by infiltrating the attackers' command-and-control infrastructure. The exposed information not only includes login credentials but also details about the affected organizations, such as industry type, revenue, and employee numbers. Independent researcher Kevin Beaumont noted that a vast majority of the compromised devices were still operational days after the breach was identified. He confirmed the authenticity of the credentials with several organizations listed in the attackers' logs. Following the initial compromise, the attackers often accessed centralized authentication systems like Radius servers and Microsoft Active Directory, raising concerns about the scale of the breach, which represents approximately half of all Fortinet firewalls that are accessible via the internet.

Cybersecurity