Fortinet confirmed customer data taken from third-party cloud file drive

Organization
Fortinet
Exploit
Third-Party Data Breach
Industry
Technology

Fortinet, one of the largest network security vendors, confirmed in September 2024 that an unauthorized individual had accessed a limited number of files stored on the company's instance of a third-party, cloud-based shared file drive. The confirmation followed a post on a cybercrime forum by an actor using the handle Fortibitch, who claimed to have taken 440GB of data from a Fortinet Azure SharePoint environment.

In its statement, Fortinet said the files included limited data related to a small number of Fortinet customers. CSO Online reported that the company put the scope at less than 0.3 percent of its customer base, while CyberInsider reported that the affected customers were in the Asia-Pacific region.

Fortinet said its operations, products and services had not been affected and that it had identified no evidence of access to any other Fortinet resource. It stressed that no ransomware was deployed, no data was encrypted and its corporate network was not reached.

According to reporting on the forum post, the actor said Fortinet had refused to negotiate over a ransom and then released credentials for an Amazon S3 bucket said to contain the stolen archive. Fortinet did not confirm what the published archive contained. The company said it had contacted the customers involved directly.

Sources