
Recent cybersecurity incidents involving Fortinet have highlighted the critical need for robust security practices among users of its products. From leaked customer data to a newly discovered zero-day vulnerability, these events underscore the evolving threats targeting even the most advanced cybersecurity solutions.
The Data Breaches
- Customer Data Breach (September 2024):
A hacker, known as “Fortibitch,” accessed Fortinet’s Azure SharePoint instance, stealing 440GB of sensitive data. The breach impacted less than 0.3% of customers and did not compromise Fortinet’s core operations or services. However, the leaked data included customer information and internal documents, raising concerns about cloud security practices. - Zero-Day Vulnerability Exploitation (CVE-2024-55591):
In January 2025, Fortinet disclosed a critical authentication bypass vulnerability in its FortiOS and FortiProxy systems. Exploited since November 2024, this flaw allowed attackers to gain super-admin privileges on vulnerable devices via specially crafted requests to a Node.js WebSocket module. The attack involved unauthorized administrative access, rogue account creation, and firewall policy manipulation. - Leaked Firewall Configurations (January 2025):
A hacking group called “Belsen Group” leaked sensitive configuration files, IP addresses, and VPN credentials for over 15,000 FortiGate devices. Although the data dated back to 2022, it still posed significant risks to organizations using unpatched systems or unchanged credentials.
The Aftermath
The breach impacted less than 0.3% of customers, but its implications reach far beyond the number. Attackers gained access to:
- Internal documents and customer information
- Firewall configurations and IP addresses
- VPN credentials and system access details
Fortinet’s Response
Fortinet acted swiftly in response to these incidents:
- Forensic Investigation: Engaged external experts to validate findings and assess the scope of breaches.
- Customer Communication: Notified affected customers and provided mitigation guidance.
- Patches and Updates: Released fixes for CVE-2024-55591 and other vulnerabilities, urging users to upgrade their systems immediately.
- Mitigation Workarounds: Advised disabling HTTP/HTTPS administrative interfaces or restricting access to trusted IPs as an interim measure.
Despite these efforts, the incidents highlight challenges in proactive threat detection and cloud security management.
Impact on Users
These breaches have far-reaching implications:
- Data Exposure: Leaked configurations and credentials could enable attackers to compromise networks further.
- Operational Risks: Exploited vulnerabilities may lead to unauthorized access, lateral movement within networks, and potential ransomware attacks.
- Reputation Damage: Organizations relying on Fortinet products may face scrutiny over their cybersecurity posture.
Preventing Future Incidents
To mitigate risks and prevent similar breaches:
- Patch Systems Regularly:
Ensure all Fortinet devices are updated with the latest firmware versions addressing known vulnerabilities like CVE-2024-55591. - Change Credentials:
Update all usernames, passwords, SSH keys, and certificates on affected devices. Avoid reusing old credentials. - Restrict Access:
Limit administrative interface access to trusted IPs using local-in policies or disable public-facing interfaces altogether. - Monitor for Threats:
Implement robust monitoring tools to detect unusual activity or Indicators of Compromise (IoCs). Engage in proactive threat hunting. - Adopt Multi-Factor Authentication (MFA):
Enforce MFA for accessing critical systems like firewalls and VPNs to reduce unauthorized access risks. - Audit Configurations:
Regularly review firewall rules and system configurations for unauthorized changes or misconfigurations. - Educate Teams:
Train employees on cybersecurity best practices and incident response protocols to enhance organizational resilience.
Looking Forward
The recent breaches affecting Fortinet users serve as a stark reminder of the importance of vigilance in cybersecurity. While Fortinet has taken commendable steps to address these issues, organizations must prioritize timely patching, robust access controls, and continuous monitoring to safeguard their networks against evolving threats. By adopting proactive security measures, businesses can better protect themselves from becoming the next target in an increasingly hostile cyber landscape.
Resources:
Rapid7 Blog: Fortinet Firewalls Hit with New Zero-Day Attack, Older Data Leak
SecurityWeek: Fortinet Data Breach Impacts Customer Information
Fortinet Blog: Notice of Recent Security Incident
Fortinet Document Library: Best Practices – FortiOS 7.2
Fortinet Community: Upgrade to FortiOS 7.0.17 to resolve vulnerability CVE-2024-55591
Fortinet Document Library: Hardening | FortiGate / FortiOS 7.6.0
Fortinet Document Library: Security Best Practices | FortiManager 7.6.0
Hardening the network edge, in priority order
Edge devices such as firewalls and VPN appliances are attacked constantly because they are reachable from the internet by definition and they sit at a trusted point in the network. Treat them as your most exposed assets rather than as infrastructure that runs quietly.
- Take management interfaces off the public internet. Administrative access to a firewall or VPN appliance should never be reachable from anywhere. Restrict it to an internal network or a dedicated management path.
- Patch edge devices faster than anything else you own. Vulnerabilities in these products are exploited within days of disclosure, and often before a fix exists.
- Require multi factor authentication for VPN access without exception, including service and contractor accounts, which are the ones usually granted an exemption and then forgotten.
- Rotate credentials after any vendor incident. If configuration data may have leaked, assume the credentials inside it are known. That includes local administrator accounts and pre shared keys.
- Send device logs somewhere else. An attacker who reaches the device can clear its logs. Logs shipped off the device in real time are what let you reconstruct what happened.
- Review the rule base once a year. Firewall rules accumulate. Old permit rules for decommissioned systems are quiet openings nobody remembers creating.
One further point that gets missed. When a vendor publishes a fix, read whether the advisory also tells you to check for signs of prior compromise. Patching closes the door, but it does not remove anyone already inside, and several edge device incidents have involved organizations that patched promptly and stopped there.
After patching, check whether anyone is already inside
Edge device advisories often mention indicators of compromise, and those sections get skipped because patching feels like completion. It is not. If a device was vulnerable and reachable, assume it may have been reached and look for the evidence.
At minimum, review administrative account lists for entries nobody recognizes, check for configuration changes around the disclosure date, look for new or modified VPN accounts, and confirm no unexpected tunnels or routes exist. If logs were only stored on the device itself, treat their absence as an open question rather than as reassurance.
How Secur-IT Data Solutions can help
We manage and monitor network edge infrastructure for organizations across the GTA, which covers patching on a schedule that matches the risk, log collection off the device, and periodic rule base reviews. Where an incident has already happened, we help establish whether anything was left behind. We work with organizations across Toronto and the GTA as their managed security provider, and we are happy to start with a conversation rather than a quote. Get in touch with our team and we will tell you honestly whether this is something you need help with or something you can close yourself.

Krikor Tengerian is the CEO and founder of Secur-IT Data Solutions, a Toronto-based cybersecurity firm focused on helping Canadian organizations secure their infrastructure and critical systems. With over 25 years of experience across cybersecurity and IT infrastructure, he has supported organizations in hardening networks, protecting critical workloads, and aligning security controls with business and regulatory requirements.
Krikor actively shapes the direction and themes of Secur-IT’s educational content, collaborating with AI tools to structure, refine, and expand articles while providing the real-world context, use cases, and review to keep them accurate and practical for readers. He regularly shares insights on OT security, threat detection, incident response, and Canadian cybersecurity compliance to help industrial and commercial organizations better understand and reduce their cyber risk.



