Close Menu
    Facebook LinkedIn YouTube Instagram X (Twitter)
    Blue Tech Wave Media
    Facebook LinkedIn YouTube Instagram X (Twitter)
    • Home
    • Leadership Alliance
    • Exclusives
    • Internet Governance
      • Regulation
      • Governance Bodies
      • Emerging Tech
    • IT Infrastructure
      • Networking
      • Cloud
      • Data Centres
    • Company Stories
      • Profiles
      • Startups
      • Tech Titans
      • Partner Content
    • Others
      • Fintech
        • Blockchain
        • Payments
        • Regulation
      • Tech Trends
        • AI
        • AR/VR
        • IoT
      • Video / Podcast
    Blue Tech Wave Media
    Home » LACNIC exposes leak of thousands of Fortinet device credentials
    Fortinet
    Fortinet
    IT Infrastructure

    LACNIC exposes leak of thousands of Fortinet device credentials

    By Fiona XuJanuary 24, 2025No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    • A data breach has exposed the credentials and config files of over 15,000 Fortigate devices, with some passwords stored in plain text.
    • This incident is linked to a zero-day vulnerability exploited by hackers, raising significant concerns about cybersecurity across affected networks.

    What happened: Fortinet credentials leaked in massive breach

    A significant data breach has emerged as a group of criminals leaked the configuration files, IP addresses, and VPN access credentials of over 15,000 Fortigate devices on the dark web. Each folder contained a Fortigate config dump file alongside a vpn-passwords.txt file. Alarmingly, some passwords were stored in plain text, likely due to poor complexity or system configuration.

    This breach is linked to a zero-day vulnerability (CVE-2022-40684) that hackers exploited by downloading configurations from compromised FortiGate devices. They created an administrator account named ‘fortigate-tech-support’ to facilitate their access.

    Although the data was collected in 2022, it reveals critical information about network defences, including firewall rules and sensitive credentials. LACNIC CSIRT has analysed the associated IP addresses and identified the countries affected within the LACNIC region, highlighting the extensive reach of this security incident.

    Also read: KSC becomes Fortinet Advanced Partner, elevating network security standards
    Also read:
     Fortinet’s 2H 2023 threat report: Key insights and imperatives

    Why it’s important

    This breach underscores the ongoing vulnerabilities within critical cybersecurity infrastructure, particularly in devices widely used across various sectors. The exposure of Fortinet credentials not only jeopardises the security of individual organisations but also poses a broader risk to the interconnected systems that rely on these devices. As cybersecurity threats become more sophisticated, incidents like this serve as a wake-up call for all organisations to reassess their security protocols.

    This leak follows a troubling trend in the tech industry, where high-profile breaches have become alarmingly common. For example, the previous incident involving the leakage of 500,000 credentials from Fortinet devices illustrates a pattern of negligence in securing sensitive data. Such events highlight the necessity for robust security measures and regular firmware updates, as recommended by experts.

    As digital transformation accelerates, the stakes are higher than ever. Cybersecurity breaches not only affect the immediate victims but can have ripple effects across entire networks. This story impacts readers by emphasising the importance of vigilance in securing their digital assets, urging them to implement best practices and stay informed about potential vulnerabilities. In an era where data is the new currency, understanding these risks is crucial for safeguarding both personal and organisational information.

    cybersecurity vulnerabilities Fortinet data breach
    Fiona Xu

    Fiona Xu is an intern reporter at BTW Media, having studied Media Management at Hong Kong Baptist University. She specialises in tech reporting and investigative journalism. Contact her at f.xu@btw.media.

    Related Posts

    Cloud Innovation calls for AFRINIC wind-up after ‘impossible’ election standards

    July 11, 2025

    Fimnet: Enabling Kenya’s Digital Growth

    July 11, 2025

    CoLi Link Ghana Limited: Pioneering connectivity

    July 11, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    CATEGORIES
    Archives
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023

    Blue Tech Wave (BTW.Media) is a future-facing tech media brand delivering sharp insights, trendspotting, and bold storytelling across digital, social, and video. We translate complexity into clarity—so you’re always ahead of the curve.

    BTW
    • About BTW
    • Contact Us
    • Join Our Team
    TERMS
    • Privacy Policy
    • Cookie Policy
    • Terms of Use
    Facebook X (Twitter) Instagram YouTube LinkedIn

    Type above and press Enter to search. Press Esc to cancel.