The encyclopedia · Software & IT · Technical decision · 2025
Fortinet left its own data on an unguarded cloud drive — a hacker sold 440GB of it
In January 2025 a hacker named 'Fortibitch' claimed 440GB of Fortinet's files — and the firm that sells security had been breached itself.
Fortinet · 2025-01-14
What happened
In mid-January 2025 a threat actor using the handle 'Fortibitch' began posting on a hacker forum, claiming to have stolen roughly 440GB of data from Fortinet, one of the world's largest network-security vendors. The actor said the haul — dubbed 'Fortileak' — had been pulled from a Microsoft Azure-hosted SharePoint file drive Fortinet used as a shared, external file-storage platform, and offered the data for sale after publishing small sample files as proof.
Fortinet confirmed the intrusion with an unusual admission: it told customers that a 'limited' amount of data had been accessed by 'an individual threat actor' via a third-party, cloud-based shared file drive, and that the attacker had then posted and sold the files. The company's own PSIRT blog downplayed the scale, arguing the actor's 440GB claim was misleading because the drive contained a mix of employee and customer data, some of it duplicates, and said the incident affected only a fraction of one percent of customers.
The breach was notable mostly for who it happened to: a company whose entire product line exists to stop exactly this. Fortinet sells firewalls and security software to tens of thousands of organisations, and its customers had to be told that a vendor trusted with their defensive infrastructure could not keep its own documents locked down. The company said it engaged a third-party investigator, revoked the attacker's access, and warned that the leaked data could be used in social-engineering or phishing attacks against its customers.
Why it happened
- Fortinet stored customer-related and corporate documents on an externally hosted cloud drive that a single threat actor could reach and exfiltrate.
- The security vendor did not apply the same segmentation and access control to its own file storage that it sells to customers.
- The incident became public through the attacker's forum post, not Fortinet's own disclosure, so the company was always reacting.
The lesson
A security company is judged by the same standard it sells. If your own shared cloud drive is reachable by a single outsider, the firewall you sell is doing less work than the one you run.
Aftermath
Fortinet confirmed the breach to customers, engaged forensic investigators, revoked the attacker's access, and warned that leaked materials could be used to target customers with phishing. The 'Fortibitch' persona and the 'Fortileak' dump became shorthand in security circles for the awkwardness of a vendor whose own house was not in order — and a reminder that the storage layer is often the softest part of even a security vendor's estate.
Sources
- Fortinet PSIRT — Analysis of Threat Actor Data Posting
- BleepingComputer — Fortinet confirms data breach after hacker claims to steal 440GB of files
- The Cyber Express — Fortinet data breach: hacker claims 440GB heist
- DataBreachToday — Fortinet confirms limited data breach after hacker leaks 440 GB
spotted an error? The club wants to know.
More like this
A software change took Verizon's 5G core down 10 hrs — 2M lost calling, texting and 911
Meta's 'designed for privacy' glasses shipped users' intimate footage to Kenya reviewers
Microsoft 365 falls for five hours after a maintenance bug cut West US off the network
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.