Clever password-stealing assault targets 75k Fortinet firewalls

Clever Data Breach Disturbs Fortinet Users

Credentials Stolen from 75,000 Fortinet Firewalls

Oi, if you’ve got a Fortinet firewall, it’s high time to pull yourself together and change those passwords fast. Some audacious individuals have managed to infiltrate approximately 75,000 Fortinet firewall devices and swipe credentials from prominent companies across 194 nations, creating quite a stir. It appears some networks have been thoroughly breached. The experts claim they’ve confirmed the data and believe that the compromised FortiGate passwords are linked to accounts from major players such as Samsung, FoxConn, Comcast, Siemens, Lenovo, and many others. Be sure to verify if your organization is on the naughty list and promptly update all passwords related to Fortinet VPN and admin interfaces. And don’t forget to enable multi-factor authentication, as this sort of security lapse could allow attackers to waltz straight through, not only your firewall but your entire network. Sounds like a jolly day for them, eh?

The Worldwide Consequence of FortiBleed

Our friends at Hudson Rock, who’ve been examining the data, state that this leak impacts 21,632 unique domains. “This breach strikes almost every shady corner of the global economy, leaving no stone unturned,” they mentioned on their Infostealer blog. Researcher Volodymyr “Bob” Diachenko identified the intrusions and pointed out a Russian-speaking group. “These folks intercept SSL VPN authentication, crack hashes using a 45-GPU cluster with Hashtopolis, and sneak into internal Active Directory environments,” he remarked on LinkedIn. “The operation ran through 1.16 billion credential attempts on 320,777 FortiGate targets and 2.1 billion attempts against 163,650 MSSQL servers.”

Complete Takeover and Confidential Document Theft

And get this, the criminals even completely compromised at least four organizations, including a Turkish NATO defense contractor, stealing some highly classified defense documents in the process. Security investigator Kevin Beaumont also took a look and confirmed “the data is authentic.” “I’ve worked with several listed organizations and can attest to the logins and passwords being the genuine article,” Beaumont posted. “Many of these devices are running relatively up-to-date patches, mind.”

What Comes Next?

Shodan estimates this enormous theft encompasses about half of all internet-exposed Fortinet firewalls. Beaumont also highlighted that most of these compromised Fortinet devices are still operational. So if you’re still reading: stop right now, and go reset your Fortinet firewall passwords immediately. We’ve reached out to Fortinet and the affected companies regarding this entire FortiBleed incident for a statement. Lenovo’s looking into it; we haven’t received responses from the others yet. Cheers, folks.

Conclusion

The GadgetLad Summary: Fortinet Debacle – Secure Those Passwords, Everyone!

In summary, if you’ve got a Fortinet firewall, it’s time for a password reevaluation before some unsavory character breaks in and helps themselves to your entire network. With names like Samsung and Lenovo involved, it’s safe to assert that this breach is no trivial matter. Get it sorted before it sorts you out!