Cyber Security News

Threat Actor Claims Fortinet Data Breach via Third-Party Service

A threat actor claimed unauthorized access to a third-party cloud-based file-sharing service used by Fortinet. The incident reportedly affected several Fortinet customers in the Asia-Pacific region.

“An individual gained unauthorized access to a limited number of files stored on Fortinet’s instance of a third-party cloud-based shared file drive, which included limited data related to a small number of Fortinet customers, and we have communicated directly with customers as appropriate,” Fortinet spokesperson said to Cyber Daily.

The company stated that there is currently no indication that the incident has resulted in any malicious activity impacting customers and that Fortinet’s operations, products, and services remain unaffected.

Decoding Compliance: What CISOs Need to Know – Join Free Webinar

Fortinet is the third-largest cybersecurity firm with a valuation of $60 billion, known for providing endpoint security, firewalls, and other solutions to organizations worldwide, including critical infrastructure in Australia. The company has invested heavily in the Australian federal and defense market.

Interestingly, the threat actor on a hacking forum has claimed to have leaked 440 GB of data from Fortinet’s Azure SharePoint. However, it remains to be verified if this claim is connected to the confirmed third-party data breach incident.

Hacking Forum post (Source: HackManac)

HackManac states, “the post from the threat actor on the hacking forum is connected remains to be verified.”

As the story develops, it remains unclear whether any data about the government agencies or critical infrastructure was compromised, and the identity of the threat actor behind the breach is currently unknown.

Fortinet and relevant authorities are likely to provide updates as more information comes to light.

Simulating Cyberattack Scenarios With All-in-One Cybersecurity Platform – Watch Free Webinar

Guru Baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Hackers Trick Users to Download Weaponized Microsoft Teams to Gain Remote Access

A sophisticated cyber campaign is exploiting the trust users place in popular collaboration software, tricking…

6 hours ago

New Harrods Data Breach Exposes 430,000 Customer Personal Records

Luxury department store Harrods has disclosed a significant data breach affecting approximately 430,000 customer records…

7 hours ago

New Spear-Phishing Attack Delivers DarkCloud Malware to Steal Keystrokes, FTP Credentials and Others

A newly observed spear-phishing campaign is leveraging sophisticated social engineering lures to distribute DarkCloud, a…

9 hours ago

SVG Security Analysis Toolkit to Detect Malicious Scripts Hidden in SVG Files

As attackers increasingly leverage Scalable Vector Graphics (SVG) for stealthy code injection, security researchers face…

9 hours ago

New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data

A sophisticated malware campaign has emerged that weaponizes seemingly legitimate productivity tools to infiltrate systems…

9 hours ago

JLR Confirms Phased Restart of Operations Following Cyber Attack

Jaguar Land Rover (JLR) has confirmed it will begin a phased restart of its manufacturing…

9 hours ago