Skip to main content

Hackers claim 440GB of user data breached from large cybersecurity company

Cybersecurity firm Fortinet has confirmed that user data has been taken from its Microsoft Sharepoint server and was posted to a hacking forum early this morning, as BleepingComputer reports.

The threat actor, “Fortib**ch,” shared the credentials to an alleged S3 bucket (a digital box to store files online) for others to download, claiming the total is 440GB.

Recommended Videos

Although the threat actor tried to extort Fortinet, the cybersecurity company refused to pay. The cybersecurity company has already communicated with affected users regardin,g the issue but has not confirmed the specific data the threat actor took.

In response to questions by BleepingComputer, the cybersecurity company said: “An individual gained unauthorized access to a limited number of files stored on Fortinet’s instance of a third-party cloud-based shared file drive, which included limited data related to a small number of Fortinet customers.”

For now, the company has not confirmed how many users are affected, but said it did affect those located in the Asia-Pacific region. The incident has not impacted operations at the company, and services are still running smoothly.

Hopefully, the information about how many were affected will be released soon. Unfortunately, this isn’t the only time Fortinet has had a similar incident, as Chinese hackers allegedly breached 20,000 protected systems worldwide over a few months between 2022 and 2023 to inject malware into a weak network.

The Sunnyvale, California-based company sells secure networking products like VPN services, routers, and firewalls. It is valued at nearly $60 billion and is one of the most prominent players in the cybersecurity industry.

This incident is just one of many data breaches recently reported. Earlier this week, 1.7 million users’ credit card info was stolen from payment gateway provider Slim CD.

Judy Sanhz
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Lapsus$ hackers convicted of breaching GTA 6, Nvidia, and more
A hacker typing on an Apple MacBook laptop, which shows code on its screen.

The Lapsus$ hacking gang caused havoc in 2021 and 2022 with a series of high-profile security breaches and ransom demands. Yet things have been very quiet since then, and two alleged members of the group have just been convicted in the U.K., potentially bringing an end to one of the most notable hacking sprees in recent times.

According to Bloomberg and the BBC, two people accused of being members of the gang were convicted in the U.K. of a number of crimes, including serious computer misuse, blackmail, and fraud. The defendants included Arion Kurtaj, 18, and a 17-year-old male who could not be named due to his age. Both defendants are autistic and psychiatrists deemed that Kurtaj was not fit to stand trial, so he did not give evidence. They will both be sentenced at a later date.

Read more
Hackers are pretending to be cybersecurity firm to lock your entire PC
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.

As hackers come up with new ways to attack, not even trustworthy names can be taken at face value. This time, a ransom-as-a-service (RaaS) attack is being used to impersonate a cybersecurity vendor called Sophos.

The RaaS, referred to as SophosEncrypt, can take hold of your files -- or even your whole PC -- and requires payment to have them decrypted.

Read more
A massive data breach has left Intel scrambling for solutions
A render of an Intel Core HX chip.

A security breach in March robbed MSI of up to 1.5TB of sensitive data. However, MSI is not the only company impacted.

As a result of the breach, Intel is now investigating a major leak of Intel Boot Guard keys. The extent of the damage is still unclear, but the worst-case scenario is that the security feature is now useless on compromised devices -- and that's a pretty lengthy list.

Read more