Institution Profiling / Internet infrastructure institution

LACNIC exposes leak of thousands of Fortinet device credentials

LACNIC exposes leak of thousands of Fortinet device credentials is tracked as a internet infrastructure institution within the internet infrastructure ecosystem.

LACNIC exposes leak of thousands of Fortinet device credentials
Caption: LACNIC exposes leak of thousands of Fortinet device credentials visual context for BTW intelligence coverage. · Source context: Existing article media was retained or restored as the subject-specific visual basis. · Relevance reason: LACNIC exposes leak of thousands of Fortinet device credentials is the primary subject or event subject; the image supports the article's governance reading. · Image provenance: Existing curated article image retained because it is subject- or event-specific and not a generic pool placeholder.

Sources

Public references used for this article.

CategoryInstitution

LACNIC exposes leak of thousands of Fortinet device credentials is tracked as a internet infrastructure institution within the internet infrastructure ecosystem.

RegionLatin America and Caribbean

LACNIC exposes leak of thousands of Fortinet device credentials has public-source relevance to network operations, governance, dependency mapping, or market structure.

Signal FocusInternet infrastructure institution

LACNIC exposes leak of thousands of Fortinet device credentials has public-source relevance to network operations, governance, dependency mapping, or market structure.

Content TypeProfile

LACNIC exposes leak of thousands of Fortinet device credentials is tracked as a internet infrastructure institution within the internet infrastructure ecosystem.

Primary DomainSecurity

Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.

TopicInternet infrastructure institution

LACNIC exposes leak of thousands of Fortinet device credentials is profiled by BTW Media because published evidence links it to internet infrastructure, governance, operational dependencies, or market visibility.

ImpactMedium

Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.

Confidence?Confidence Grade
0.90–1.00AHigh — direct sources
0.75–0.89A/BStrong
0.55–0.74B/CMedium
0.35–0.54C/DWeak–medium
0.10–0.34DWeak signal
0.00–0.09DInternal monitoring
Limited confidence (80%)

Several public sources

LACNIC exposes leak of thousands of Fortinet device credentials is profiled by BTW Media because published evidence links it to internet infrastructure, governance, operational dependencies, or market visibility.

  • A data breach has exposed the credentials and config files of over 15,000 Fortigate devices, with some passwords stored in plain text.
  • This incident is linked to a zero-day vulnerability exploited by hackers, raising significant concerns about cybersecurity across affected networks.

What happened: Fortinet credentials leaked in massive breach

A significant data breach has emerged as a group of criminals leaked the configuration files, IP addresses, and VPN access credentials of over 15,000 Fortigate devices on the dark web. Each folder contained a Fortigate config dump file alongside a vpn-passwords.txt file. Alarmingly, some passwords were stored in plain text, likely due to poor complexity or system configuration.

This breach is linked to a zero-day vulnerability (CVE-2022-40684) that hackers exploited by downloading configurations from compromised FortiGate devices. They created an administrator account named ‘fortigate-tech-support’ to facilitate their access.

Although the data was collected in 2022, it reveals critical information about network defences, including firewall rules and sensitive credentials. LACNIC CSIRT has analysed the associated IP addresses and identified the countries affected within the LACNIC region, highlighting the extensive reach of this security incident.

Also read: KSC becomes Fortinet Advanced Partner, elevating network security standards
Also read:
Fortinet’s 2H 2023 threat report: Key insights and imperatives

Why it’s important

This breach underscores the ongoing vulnerabilities within critical cybersecurity infrastructure, particularly in devices widely used across various sectors. The exposure of Fortinet credentials not only jeopardises the security of individual organisations but also poses a broader risk to the interconnected systems that rely on these devices. As cybersecurity threats become more sophisticated, incidents like this serve as a wake-up call for all organisations to reassess their security protocols.

This leak follows a troubling trend in the tech industry, where high-profile breaches have become alarmingly common. For example, the previous incident involving the leakage of 500,000 credentials from Fortinet devices illustrates a pattern of negligence in securing sensitive data. Such events highlight the necessity for robust security measures and regular firmware updates, as recommended by experts.

As digital transformation accelerates, the stakes are higher than ever. Cybersecurity breaches not only affect the immediate victims but can have ripple effects across entire networks. This story impacts readers by emphasising the importance of vigilance in securing their digital assets, urging them to implement best practices and stay informed about potential vulnerabilities. In an era where data is the new currency, understanding these risks is crucial for safeguarding both personal and organisational information.

At A Glance

  • Name: LACNIC exposes leak of thousands of Fortinet device credentials
  • Type: Internet infrastructure institution
  • Base: Latin America and Caribbean
  • Profile focus: Institution

What It Does

  • Public records support monitoring of its role, services, and key relationships.

Why It Matters

  • Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.
  • Operational criticality: Medium
  • Time horizon: Next quarter

What To Watch

  • Monitoring focuses on verified service continuity, governance changes, and relationship signals.
NowMedium priority

Track verified source updates, role changes, and current public evidence.

QuarterMedium policy sensitivity

Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.

YearNext quarter outlook

Longer-term relevance depends on verified operating, policy, and relationship changes.

Member Briefing

Deeper Profile Context

Login is required to unlock the full profile briefing and source notes.

Only for Strategy Circle

Strategic Circle Access

Open to all readers. Unlock profile briefings after joining and logging in.

Join Strategic Circle

Only for Leadership Alliance

Leadership Alliance Access

For owners and management of IP-holding companies. Login required to unlock.

Join Leadership Alliance
← BackAll Companies