THREAT LEVEL - HIGH

16-09-2024

Recent Security Breach Impacting Fortinet Systems

Threat Level Description

IthacaLabs has maintained the Threat Level (High) adding a new observation:

Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.

Description

We have observed that a recent security breach has impacted Fortinet’s systems, potentially exposing sensitive data.

An attacker, managed to gain unauthorized access to Fortinet’s Microsoft SharePoint server, possibly stealing approximately 440GB of confidential files. The breach was disclosed by Fortinet after the hacker, operating under the alias “Fortibitch,” attempted to extort the company.

Fortinet has confirmed that this breach affected a small percentage of its customers, less than 0.3%. However, the corporate network, critical systems, and customer-targeting mechanisms were not compromised. Fortinet is actively investigating the incident while advising its users to remain vigilant and ensure best security practices.

Although specific details about the stolen data and potential exploitation methods remain unclear, there is no evidence that this breach involved ransomware or malicious actions directed at customers.

 

Recommendation(s)

You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.

The guidelines below will help you protect against security threats:

  • Install anti-virus and spyware detection software on all computer systems. Free software may not provide protection against the latest threats compared with an industry standard product.
  • Update your computers regularly with the latest versions and patches of both antivirus and antispyware software.
  • Ensure computers are patched regularly, particularly operating system and key application with security patches.
  • Back up your data. The single biggest thing that will defeat ransomware is having a regularly updated backup.
  • It is strongly recommended to implement a Security Awareness program, addressed to all your management and staff, designed to increase the level of understanding regarding Social Engineering and security threats in general.

References:

SIGN UP

Get the latest Threat Alerts in your inbox.