LACNIC exposes leak of thousands of Fortinet device credentials is profiled by BTW Media because published evidence links it to internet infrastructure, governance, operational dependencies, or market visibility.
LACNIC exposes leak of thousands of Fortinet device credentials is tracked as a internet infrastructure institution within the internet infrastructure ecosystem.
LACNIC exposes leak of thousands of Fortinet device credentials has public-source relevance to network operations, governance, dependency mapping, or market structure.
LACNIC exposes leak of thousands of Fortinet device credentials has public-source relevance to network operations, governance, dependency mapping, or market structure.
LACNIC exposes leak of thousands of Fortinet device credentials is tracked as a internet infrastructure institution within the internet infrastructure ecosystem.
Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.
LACNIC exposes leak of thousands of Fortinet device credentials is profiled by BTW Media because published evidence links it to internet infrastructure, governance, operational dependencies, or market visibility.
Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.
| 0.90–1.00 | A | High — direct sources |
| 0.75–0.89 | A/B | Strong |
| 0.55–0.74 | B/C | Medium |
| 0.35–0.54 | C/D | Weak–medium |
| 0.10–0.34 | D | Weak signal |
| 0.00–0.09 | D | Internal monitoring |
Several public sources
- A data breach has exposed the credentials and config files of over 15,000 Fortigate devices, with some passwords stored in plain text.
- This incident is linked to a zero-day vulnerability exploited by hackers, raising significant concerns about cybersecurity across affected networks.
What happened: Fortinet credentials leaked in massive breach
A significant data breach has emerged as a group of criminals leaked the configuration files, IP addresses, and VPN access credentials of over 15,000 Fortigate devices on the dark web. Each folder contained a Fortigate config dump file alongside a vpn-passwords.txt file. Alarmingly, some passwords were stored in plain text, likely due to poor complexity or system configuration.
This breach is linked to a zero-day vulnerability (CVE-2022-40684) that hackers exploited by downloading configurations from compromised FortiGate devices. They created an administrator account named ‘fortigate-tech-support’ to facilitate their access.
Although the data was collected in 2022, it reveals critical information about network defences, including firewall rules and sensitive credentials. LACNIC CSIRT has analysed the associated IP addresses and identified the countries affected within the LACNIC region, highlighting the extensive reach of this security incident.
Also read: KSC becomes Fortinet Advanced Partner, elevating network security standards
Also read: Fortinet’s 2H 2023 threat report: Key insights and imperatives
Why it’s important
This breach underscores the ongoing vulnerabilities within critical cybersecurity infrastructure, particularly in devices widely used across various sectors. The exposure of Fortinet credentials not only jeopardises the security of individual organisations but also poses a broader risk to the interconnected systems that rely on these devices. As cybersecurity threats become more sophisticated, incidents like this serve as a wake-up call for all organisations to reassess their security protocols.
This leak follows a troubling trend in the tech industry, where high-profile breaches have become alarmingly common. For example, the previous incident involving the leakage of 500,000 credentials from Fortinet devices illustrates a pattern of negligence in securing sensitive data. Such events highlight the necessity for robust security measures and regular firmware updates, as recommended by experts.
As digital transformation accelerates, the stakes are higher than ever. Cybersecurity breaches not only affect the immediate victims but can have ripple effects across entire networks. This story impacts readers by emphasising the importance of vigilance in securing their digital assets, urging them to implement best practices and stay informed about potential vulnerabilities. In an era where data is the new currency, understanding these risks is crucial for safeguarding both personal and organisational information.
At A Glance
- Name: LACNIC exposes leak of thousands of Fortinet device credentials
- Type: Internet infrastructure institution
- Base: Latin America and Caribbean
- Profile focus: Institution
What It Does
- Public records support monitoring of its role, services, and key relationships.
Why It Matters
- Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.
- Operational criticality: Medium
- Time horizon: Next quarter
What To Watch
- Monitoring focuses on verified service continuity, governance changes, and relationship signals.
Track verified source updates, role changes, and current public evidence.
Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.
Longer-term relevance depends on verified operating, policy, and relationship changes.
Member Briefing
Deeper Profile Context
Login is required to unlock the full profile briefing and source notes.
Only for Strategy Circle
Strategic Circle Access
Open to all readers. Unlock profile briefings after joining and logging in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance Access
For owners and management of IP-holding companies. Login required to unlock.
Join Leadership Alliance





