2024-09-13
Fortinet Customer Data Accessed and Possibly Leaked
440GB of data in an Amazon S3 bucket, shared in a hacking forum, allegedly contains data exfiltrated from Fortinet. The company reported in a blog post that a threat actor gained unauthorized access to customer data stored in a 'third-party cloud-based shared file drive,' but that the breach impacted less than 0.3 percent of their customers. Fortinet has not confirmed the leakers' claims that their CEO received and declined a ransom demand, and has expressed confidence that the attack does not merit an 8-K filing.
Editor's Note
I have yet to see the datasets personally. From what the threat actor says, this appears to be related to all their SharePoint data. 440GB of something is not small in any way. This may be one of the most significant vendor breaches in quite some time. This will take time to download and review, so expect fall out from this for some time.
Moses Frost
The attacker claims they exploited a weakness in their Azure SharePoint site, accessing about 440GB and the Fortinet CEO walked away from ransom negotiations. While I'm not so sure 440GB qualifies as a limited amount of data, they still have the latitude of material impact to temper the requirement of filing the K-8. This has been a bit of a rough year for Fortinet, with critical fixes in January and February, as well as FortiGate firewall compromises in June, which means they need to downshift into full transparency, particularly with recent DLP and cloud security acquisitions, which they could highlight for their role in reducing the scope of the compromise or mitigating future incidents, so they can focus on remediation and mitigations rather than responding to external claims.