2024 Fortinet — third-party cloud shared-drive access; <0.3% customer-related files (disclosed Sep)
Data compromised
Customer-related files on affected shared drive—categories described as limited in vendor language
Technical writeup
On 12 September 2024, Fortinet posted a Notice of Recent Security Incident describing unauthorized access to a limited number of files on a third-party cloud-based shared file drive, including data related to less than 0.3% of customers, with no ransomware, no corporate network intrusion, and products/services described as unaffected in the vendor statement. Outlets tied public disclosure timing to criminal-forum marketing of alleged file exfiltration; Fortinet did not uniformly publish a per-field victim census in the first disclosure wave.
Root cause
Unauthorized third-party cloud shared-storage access (root intrusion vector not fully detailed publicly)