Security
FBI and Secret Service warn FortiBleed campaign still active after 86,644 devices hit
FortiBleed is still locking Fortinet users out and feeding ransomware crews, while Denmark, Arizona, Georgia Power and one vengeful engineer round out today's security ledger.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
FBI and Secret Service: FortiBleed still active, locks users out and feeds ransomware
An FBI and Secret Service alert published Tuesday says FortiBleed, a credential compromise campaign against Fortinet firewalls and VPN gateways, remains an active threat that can lock users out of their accounts and lead to ransomware attacks. When first uncovered earlier this year, SOCRadar verified more than 86,644 compromised devices across 194 countries; its chief information security officer, Ensar Seker, said a later investigation identified more than 400,000 firewalls targeted by the wider operation. Attackers use stolen credentials to reach exposed Fortinet devices, create new admin accounts and sometimes lock out real owners, so patching and password resets alone are insufficient. Initial access brokers are supplying ransomware affiliates including INC/Lynx and Payload. The agencies urge restricting or removing internet administration, resetting credentials, enabling multifactor authentication and reviewing logs.
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks →
Denmark confirms CPR breach exposing data of 8.8 million people
The Danish government confirmed what it called a deeply serious incident in which hackers accessed the Central Person Register (CPR), exposing personal data belonging to 8.8 million citizens. According to an October 5 statement, the attackers gained access by exploiting a Danish company’s legitimate access to the system. The data accessed includes names, addresses and CPR numbers, which link to healthcare and other services. Irregular system behavior was observed during September, and the attack was spotted on Friday night. Minister of research, education and digitalization Christina Egelund said authorities are still mapping the full extent. Denmark’s population is about six million, but the register holds data on roughly 11 million people, including emigrants and the deceased. The incident was reported to the Danish data protection regulator and local police are investigating.
Danish data breach: Everything we know about the cyber attack that hit 8.8m Danes →
Arizona court phishing attack exposes data on 1.3 million people
An Arizona court employee clicking a malicious phishing link led to a breach affecting more than one million people in the court system, a spokesperson confirmed Tuesday. The September 24 attack copied personally identifiable information related to roughly 1.3 million people in the court’s Fines/Fees and Restitution Enforcement Program. It also copied data from the Arizona Foster Care Review Board, including over 150,000 records dating back to 2010, with general case information, child information, names and statements of interested parties, and recommendations for the court. Active dependency cases are not expected to be affected. Arizona Supreme Court Chief Justice Ann Scott Timmer said IT staff learned of the attack and stopped it as quickly as possible, and that the court was in touch with those affected.
Arizona Court Cyberattack Exposes Data on 1.3 Million People →
Georgia Power says hackers accessed 400,000 customer accounts
Georgia Power detected unauthorized access to its online customer portal, exposing account information for approximately 400,000 customers tied to parent company Southern Company, of which 300,000 were Georgia Power customers. The exposed data included names, addresses, phone numbers, email addresses and the last four digits of Social Security numbers. Bank account numbers, payment card information and driver’s license numbers were not accessed. The company said it halted the activity on detection and contacted law enforcement; an investigation found no evidence that unauthorized access is continuing. The third party’s identity has not been released. Georgia Power is notifying affected customers and has arranged one year of complimentary credit monitoring and identity theft restoration through Equifax, and warned customers about impersonation attempts.
Georgia Power says hackers accessed 400,000 customer accounts →
Engineer gets 32 months for locking 3,000-plus devices in extortion plot
Daniel Rhyne, 57, of Kansas City, Missouri, a former core infrastructure engineer at a New Jersey industrial company, was sentenced to 32 months in prison for locking thousands of devices on his employer’s network in a ransomware-style attack. He pleaded guilty to a failed extortion plot and was arrested in August 2024. Between November 8 and November 25, Rhyne used an administrator account without authorization, changed the domain administrator password to TheFr0zenCrew!, deleted 13 domain admin accounts and changed passwords for 301 domain user accounts. Scheduled tasks blocked access to 254 servers and 3,284 workstations, and he shut down random machines in December 2023. On November 25 he sent coworkers a ransom email titled Your Network Has Been Penetrated, demanding 20 bitcoin, roughly $750,000 at the time.
Engineer sentenced for locking over 3,000 devices on employer network →