: Investigations suggest the data was likely stolen in late 2022 . The leak is believed to be the result of attackers exploiting a specific authentication bypass vulnerability, CVE-2022-40684 , which allowed administrative access to affected FortiOS, FortiProxy, and FortiSwitchManager products.

: Ensure your firmware is updated to versions that patch CVE-2022-40684 .

: The .rar archive reportedly includes sensitive information such as: IP addresses and port details. Firewall configuration settings. Hashed or plain-text VPN passwords.

Unknown group releases Fortinet config files and VPN ... - Heise

: Examine your firewall logs for any unauthorized administrative access dating back to late 2022.

Subscribe to our weekly newsletter.