Skip to content
Back to incidents
Data Leak14 January 2025

Data Leak – Danish Fortinet customers (incl. DSV, Mærsk, Rigspolitiet)

Company

Danish Fortinet customers (incl. DSV, Mærsk, Rigspolitiet)

Sector

Multiple / Cross-sector

Actor

Belsen Group

##Description

On 14 January 2025 a threat actor calling itself the Belsen Group published, for free, a 1.6 GB dataset containing configuration files, IP addresses and VPN credentials for more than 15,000 FortiGate firewalls worldwide. The dump included per-device configuration.conf files and vpn-passwords.txt, some with plaintext passwords, along with private keys and firewall rules.

Danish organisations in the dump included DSV, Mærsk and the Danish police. Forsvarets Efterretningstjeneste warned Danish Fortinet customers and advised a series of precautions.

The data was not stolen in 2025. Analysis, including by Kevin Beaumont, tied it to exploitation of CVE-2022-40684 in 2022 — meaning organisations that patched at the time, considered the matter closed, and never rotated the credentials in those configs were exposed again more than two years later by a disclosure they had no control over.

Included here as the collection's clearest example of an exposure whose blast radius is set by credential hygiene after patching, not by the patch itself.

##Timeline

  1. 2022-10

    CVE-2022-40684 exploited as a zero-day; device configurations harvested

  2. 2025-01-14

    Belsen Group publishes configs and VPN credentials for 15,000+ FortiGate devices

  3. 2025-01

    Danish organisations including DSV, Mærsk and Rigspolitiet identified in the dataset; FE issues warning to Danish Fortinet customers

##References