ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

New hacking group exposes sensitive data of over 15,000 FortiGate devices

A newly emerged hacking collective, the "Belsen Group," has publicly leaked configuration files, IP addresses, and VPN credentials of more than 15,000 FortiGate devices on the dark web. This development has sent shockwaves through cybersecurity circles. This alarming release, freely accessible to cybercriminals, contains highly sensitive technical details that pose significant risks to affected organizations.

 

The Belsen Group, which surfaced on social media and cybercrime forums earlier this month, appears to be using this breach to establish its presence in the hacking community. The group announced its actions via a Tor website and a forum post, claiming responsibility for hacking governmental and private sector targets worldwide.

 

"To solidify the name of our group in your memory, we are proud to announce our first official operation," the group declared, promoting the leak as a landmark achievement.

 

The leaked archive, 1.6 GB, is organized by country and includes subfolders for each affected device’s IP address. Cybersecurity expert Kevin Beaumont has confirmed that the archive contains configuration dumps and VPN password files, with many credentials stored in plain text. These files also include private keys and firewall rules, which could provide a roadmap for further cyberattacks against compromised networks.

 

Beaumont linked the data breach to a vulnerability tracked as CVE-2022–40684, a zero-day flaw exploited in 2022 before Fortinet issued a fix. He verified the legitimacy of the leaked data by comparing it with incident response artifacts, highlighting that the exposed credentials match those found on affected devices.

 

"The data appears to have been assembled in October 2022, during the period this zero-day vulnerability was active. For some reason, the data has only been publicly released today, over two years later," Beaumont explained in a blog post.

 

The cybersecurity community has raised concerns that, despite the age of the data, the leaked files still reveal critical information about network defenses, including firewall rules and unaltered credentials. Beaumont has advised FortiGate device administrators to review their systems immediately and change any unchanged passwords exposed in the leak.

 

A report by German news outlet Heise corroborated Beaumont’s analysis, noting that the leaked data exclusively involves FortiGate devices running FortiOS firmware versions 7.0.0 through 7.2.2, all released before October 3, 2022. This timeline aligns with the exploitation of the CVE-2022–40684 vulnerability.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543