: Because these configuration files are not typically stored centrally by the manufacturer, security experts believe the leak originated from individual firewall exploits rather than a breach of Fortinet's own systems. Response and Remediation
: Immediately change all administrative and VPN passwords.
The file is linked to a significant cybersecurity incident involving the Belsen Group (or a group using that name) that surfaced around mid-January 2025.
So the data was probably stolen in the fall of 2022, but where and how did the unknown attackers obtain the sensitive information? heise online