Exposure and threats
Exposure doesn't start when it goes public
In January 2025 the configurations of some 15,000 firewalls were published for free. They had been taken in 2022. What that says about the clock almost nobody measures.
Published January 29, 2025 · Updated September 1, 2026
On 14 January 2025 a group calling itself Belsen Group published on a Tor site, free and unconditionally, configuration files and VPN credentials for roughly 15,000 FortiGate devices, organized by country. Researcher Kevin Beaumont confirmed the data was genuine by cross-referencing it with devices visible on Shodan.
That isn't the number that matters. This is: the data had been collected in October 2022, using CVE-2022-40684, an authentication bypass Fortinet had disclosed that same month. More than two years passed between the day the data was taken and the day it was published.
The two clocks
Almost everyone measures one clock: the one that starts when the news breaks. That's the one that triggers the meetings, the internal emails and the emergency review. But another one started much earlier and nobody watched it, because it made no noise: the one that started the day someone got in.
Between those two clocks there's a period in which the organization behaves as if nothing is happening — and it has reasons to believe that, because nothing visible happened. The decisions made in that period are the ones that matter later: which credentials were rotated, which rules were reviewed, which access was revoked.
Why an old configuration still works
Intuition says a two-year-old file is worthless. With a firewall configuration, intuition fails, for a very simple reason: firewall rules barely change. They get written once, adjusted when something breaks, and left alone. Nobody rewrites them for fun.
Which means a 2022 file probably describes the 2025 network accurately: what's published and what isn't, how it's segmented, where remote support comes in, which admin users exist. Even if every password had been changed, the map is still valid. And a map saves the slow part of an attack, which is working out where you are.
What to do with this
- 1
Treat every configuration as if it contained credentials
Because it almost always does, and because it gets shared with the casualness of a technical file: over email, in a ticket, in an internal repository. The practical rule is that a configuration file is handled with the same care as a password.
- 2
Rotate by date, not by suspicion
If a credential was valid during the window in which a device could have been compromised, rotate it — even with nothing suggesting it was used. "No evidence of misuse" is reassuring and it isn't a criterion: the evidence shows up afterwards.
- 3
Know what's visible from outside, and since when
What your exposed surface is today: which ports, which admin panels, which certificates, which forgotten subdomains. It's the list an automated program builds about you in minutes and that almost no organization has about itself.
- 4
Watch your own name in other people's leaks
Your domains and your email addresses show up in third-party dumps you never had a direct relationship with. Finding out from the press, twenty months later, is the expensive way to find out.
Where we fit
Points 3 and 4 are two modules of our platform: Attack Surface builds the inventory of what you have published, from the outside, and Breach Exposure watches for your domains and email addresses appearing in known leaks. Both are inside the same subscription as the other six modules.
There's a 30-day trial, no credit card, and nothing to install: the first view comes from public records anyone can consult — it's just that nobody reviews them systematically. If what you have in front of you is an incident rather than a review, write to us — that is not something a trial handles.
Sources
- Kevin Beaumont, DoublePulsar (2025) — análisis original de la filtración
- SecurityWeek (2025) — «Data From 15,000 Fortinet Firewalls Leaked by Hackers»
- The Register (2025) — respuesta de Fortinet sobre el alcance de la filtración
Every external figure in this article carries its source. If a number can't be verified, we don't publish it.