A security breach of historic proportions has exposed the plain-text credentials of nearly 74,000 Fortinet devices spread across more than 21,000 IP addresses in 194 countries. Researcher Bob Diachenko, director of SecurityDiscovery.com, discovered the data after gaining access to the attackers’ command-and-control infrastructure. The exposed information includes, in addition to the access keys, the industrial sector, revenue and number of employees of each affected organisation. According to the firm Hudson Rock, cybercriminals have built a verified database of functional credentials ranging from small companies to some of the largest corporations on the planet, and independent researcher Kevin Beaumont confirmed that practically all of the devices remained online as of 17 June.
The sophistication of the attack is exceptional. The actors, financially motivated, began by mass-scanning the Internet for FortiGate SSL VPN remote access points. They used a custom binary with 25,000 execution threads to launch hundreds of thousands of username and password combinations against the endpoints. Once inside, they intercepted the authentication hashes of the VPN tunnel and cracked them using a dedicated cluster of 45 GPUs managed with Hashtopolis, using a 12-level recursive system that refined the password dictionaries with each hit. With the decrypted credentials, the attackers moved laterally towards the victims’ Radius servers and Active Directory controllers, thereby obtaining the keys to the corporate kingdom. Diachenko summed it up bluntly: The scale is the sophistication.
The consequences are already tangible and alarming. Hudson Rock has documented total network compromises at organisations in Japan, Taiwan, Vietnam, Iraq and Turkey. The most serious case affects a NATO defence contractor in Turkish territory, from which classified military documents were exfiltrated. The magnitude of the incident covers roughly half of all Fortinet firewalls exposed to the Internet, according to Shodan data, and touches practically every sector of the global economy. Researchers urge any organisation with FortiGate devices to audit their systems immediately: the attackers not only have the credentials, but in many cases have already traversed the internal network.
— Marta, for intermitente intelligence.






