Security

Cyber-crime

Fortinet admits miscreant got hold of customer data in the cloud

That would explain this 440GB leak, then


Fortinet has admitted that bad actors accessed cloud-hosted data about its customers, but insisted it was a "limited number" of files. The question is: how limited is "limited"?

"An individual gained unauthorized access to a limited number of files stored on Fortinet's instance of a third-party cloud-based shared file drive, which included limited data related to a small number (less than 0.3 percent) of Fortinet customers," the security giant announced in a blog post.

"Fortinet's operations, products, and services have not been impacted, and we have identified no evidence of additional access to any other Fortinet resource. The incident did not involve any data encryption, deployment of ransomware, or access to Fortinet's corporate network."

The business stated that no malicious activity directed against its customers had been detected as a result of the intrusion. It has terminated the miscreant's access to the data and called in law enforcement and notified "select cybersecurity agencies" about the incident.

On Thursday morning, meanwhile, someone calling themselves "Fortibitch" posted to a dark web forum and offered a whopping 440GB of Azure SharePoint files for download – containing Fortinet customer data stolen from an open Amazon S3 bucket. They claimed to have approached Fortinet for a ransom payment in exchange for not leaking the data, but stated the infosec business declined to cough up.

Fortibitch also accused the biz of not filing an SEC form 8-K detailing the loss – which would alert shareholders and customers. Fortinet commented that "given the limited nature of the incident, we have not experienced, and do not currently believe that the incident is reasonably likely to have, a material impact to our financial condition or operating results," so no 8-K is needed.

It wouldn't be the first, the second, or even the twentieth time a third-party supplier has been responsible for data falling into the wrong hands. But when your business is security, such incidents can cause embarrassment and reputational harm.

Fortinet has had a bad run of things this year on the security front, including:

In short, Fortinet can hardly afford to notch up more security breaches. The theft of nearly a half-terabyte of customer data is a serious business and dismissing the incident as "limited" might not be the right approach.

We'll update the story as more information comes in. ®

Send us news
5 Comments

FortiManager critical vulnerability under active attack

Security shop and CISA urge rapid action

'Satanic' data thief claims to have slipped into 350M Hot Topic shoppers info

We know where you got your skinny jeans - big deal

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets

Just how private is Apple's Private Cloud Compute? You can test it to find out

Also updates bug bounty program with $1M payout

Five Eyes nations tell tech startups to take infosec seriously. Again

Only took 'em a year to dish up some scary travel advice, and a Secure Innovation … Placemat?

Windows Themes zero-day bug exposes users to NTLM credential theft

Plus a free micropatch until Redmond fixes the flaw

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

Private equity giant Thoma Bravo adds another trophy to its growing collection

The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD

Dan O'Dowd tells El Reg about the OS secrets and ongoing clash with Musk

Millions of Android and iOS users at risk from hardcoded creds in popular apps

Azure Blob Storage, AWS, and Twilio keys all up for grabs

Beijing claims it's found 'underwater lighthouses' that its foes use for espionage

Release the Kraken!

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

Attacks on unprotected servers reach 'critical level'

Merde! Macron's bodyguards reveal his location by sharing Strava data

It's not just the French president, Biden and Putin also reportedly trackable