← Fortinet

2024 Fortinet — third-party cloud shared-drive access; <0.3% customer-related files (disclosed Sep)

2024 Unknown records affected Share on X

Data compromised

Customer-related files on affected shared drive—categories described as limited in vendor language

Technical writeup

On 12 September 2024, Fortinet posted a Notice of Recent Security Incident describing unauthorized access to a limited number of files on a third-party cloud-based shared file drive, including data related to less than 0.3% of customers, with no ransomware, no corporate network intrusion, and products/services described as unaffected in the vendor statement. Outlets tied public disclosure timing to criminal-forum marketing of alleged file exfiltration; Fortinet did not uniformly publish a per-field victim census in the first disclosure wave.

Root cause

Unauthorized third-party cloud shared-storage access (root intrusion vector not fully detailed publicly)

References