Back to the archive

The encyclopedia · Software & IT · Technical decision · 2025

Fortinet left its own data on an unguarded cloud drive — a hacker sold 440GB of it

In January 2025 a hacker named 'Fortibitch' claimed 440GB of Fortinet's files — and the firm that sells security had been breached itself.

Fortinet · 2025-01-14

What happened

In mid-January 2025 a threat actor using the handle 'Fortibitch' began posting on a hacker forum, claiming to have stolen roughly 440GB of data from Fortinet, one of the world's largest network-security vendors. The actor said the haul — dubbed 'Fortileak' — had been pulled from a Microsoft Azure-hosted SharePoint file drive Fortinet used as a shared, external file-storage platform, and offered the data for sale after publishing small sample files as proof.

Fortinet confirmed the intrusion with an unusual admission: it told customers that a 'limited' amount of data had been accessed by 'an individual threat actor' via a third-party, cloud-based shared file drive, and that the attacker had then posted and sold the files. The company's own PSIRT blog downplayed the scale, arguing the actor's 440GB claim was misleading because the drive contained a mix of employee and customer data, some of it duplicates, and said the incident affected only a fraction of one percent of customers.

The breach was notable mostly for who it happened to: a company whose entire product line exists to stop exactly this. Fortinet sells firewalls and security software to tens of thousands of organisations, and its customers had to be told that a vendor trusted with their defensive infrastructure could not keep its own documents locked down. The company said it engaged a third-party investigator, revoked the attacker's access, and warned that the leaked data could be used in social-engineering or phishing attacks against its customers.

Why it happened

  • Fortinet stored customer-related and corporate documents on an externally hosted cloud drive that a single threat actor could reach and exfiltrate.
  • The security vendor did not apply the same segmentation and access control to its own file storage that it sells to customers.
  • The incident became public through the attacker's forum post, not Fortinet's own disclosure, so the company was always reacting.
What it costa security vendor's own cloud data breached; 440GB dumpedcostly

The lesson

A security company is judged by the same standard it sells. If your own shared cloud drive is reachable by a single outsider, the firewall you sell is doing less work than the one you run.

Aftermath

Fortinet confirmed the breach to customers, engaged forensic investigators, revoked the attacker's access, and warned that leaked materials could be used to target customers with phishing. The 'Fortibitch' persona and the 'Fortileak' dump became shorthand in security circles for the awkwardness of a vendor whose own house was not in order — and a reminder that the storage layer is often the softest part of even a security vendor's estate.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →