There was a security incident at Fortinet, a provider of IT security solutions, where customer data was leaked. In a hacker forum, a user with the pseudonym "Fortibitch" offered 440 GB of data for sale, security researchers from Cloudsek report in a post. Negotiations with Fortinet are said to have failed, which means that the unknown attackers have now published the data.
Important findings
- Fortinet confirms an attack, but does not provide details about the affected data.
- 0.3% of customers are reportedly affected.
- The leaked documents contain both customer data and internal information such as marketing documents and sales figures.
- Fortinet has no evidence that the data was misused.
- Fortinet’s services were not affected by the attack.
- It is reported that the copied data was stored in a third-party cloud storage.
Details of the incident
The incident was discovered by security researchers who became aware of the sales ad on the hacker forum. The amount of data offered is considerable and could potentially contain sensitive information about Fortinet’s customers and internal processes.
Fortinet has emphasized in a statement that they currently have no signs of misuse of the data. This could indicate that the attackers may have published the data only to demonstrate their capabilities or to put pressure on the company.
Reaction of Fortinet
Fortinet has taken immediate action to review and improve the security of its systems. The company has also stressed that their services are not affected by the incident, which could provide some reassurance for their customers.
Conclusion
The incident at Fortinet again raises questions about the security of customer data in the IT industry. Organizations need to be aware of the threats and take proactive measures to protect their data. The situation remains tense, while Fortinet continues to work to clarify the incident and inform the affected customers.
Sources
- Customer data leak at IT security solutions provider Fortinet, heise online.



