Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Analyze » Fortinet » FOR1786383009

Incident Score: Analysis & Impact (FOR1786383009)

The details regarding individual company incidents & reports gives you full view from every side.

Rankiteo Score Impact Analysis

Rankiteo Incident Impact-5
Company Score Before Incident397 / 1000
Company Score After Incident392 / 1000
INCIDENT NUMBERFOR1786383009
Type of Cyber IncidentVulnerability
ATTACK VECTORExploitation of Fortinet VPN vulnerabilities, Initial access brokers
DATA EXPOSEDTens of terabytes
INCIDENT DATE31/03/2025
STATUSOngoing

Key Highlights From The Incident Analysis

  • Timeline of Fortinet's Vulnerability and lateral movement inside company's environment.
  • Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
  • How Rankiteo’s incident engine converts technical details into a normalized incident score.
  • How this cyber incident impacts Fortinet Rankiteo cyber scoring and cyber rating.
  • Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.

Full Incident Analysis Transcript

In this Rankiteo incident briefing, we review the Fortinet breach identified under incident ID FOR1786383009.

The analysis begins with a detailed overview of Fortinet's information like the linkedin page: https://www.linkedin.com/company/fortinet, the number of followers: 1310862, the industry type: Computer and Network Security and the number of employees: 16380 employees

After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 397 and after the incident was 392 with a difference of -5 which is could be a good indicator of the severity and impact of the incident.

In the next step of the video, we will analyze in more details the incident and the impact it had on Fortinet and their customers.

A newly reported cybersecurity incident, "Gunra Ransomware Group Exploits Fortinet VPN Flaws in Sophisticated Double-Extortion Attacks", has drawn attention.

A joint cybersecurity advisory from the FBI, CISA, the NSA, the U.S.

The disruption is felt across the environment, affecting VPN infrastructure, Domain controllers and Microsoft OneDrive and SharePoint, and exposing Tens of terabytes.

In response, moved swiftly to contain the threat with measures like Network segmentation and Monitoring for IOCs, and began remediation that includes Patching Fortinet VPN vulnerabilities and Enforcing MFA audits, while recovery efforts such as Offline, immutable backups continue.

The case underscores how Ongoing, teams are taking away lessons such as The incident highlights the importance of patching internet-facing VPN and RDP infrastructure, maintaining offline backups, enforcing network segmentation, and auditing authentication logic to prevent MFA bypass, and recommending next steps like Patch internet-facing VPN and RDP infrastructure immediately, Maintain offline, immutable backups in segmented locations and Enforce network segmentation to limit lateral movement, with advisories going out to stakeholders covering Organizations in healthcare, financial services, critical manufacturing, transportation, and government sectors are urged to follow mitigation recommendations.

Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.

The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.

MITRE ATT&CK® Correlation Analysis

Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Exploit Public-Facing Application (T1190) with high confidence (95%), supported by evidence indicating exploiting Fortinet VPN vulnerabilities (CVE-2024-55591, CVE-2025-24472), Valid Accounts: Cloud Accounts (T1078.004) with moderate to high confidence (85%), supported by evidence indicating compromised SSL-VPN admin account using default credentials, and Phishing: Spearphishing Attachment (T1566.001) with lower confidence (30%), supported by evidence indicating initial access brokers recruited via dark web forums (implied). Under the Credential Access tactic, the analysis identified Brute Force: Password Guessing (T1110.001) with moderate to high confidence (70%), supported by evidence indicating compromised SSL-VPN admin account using default credentials, Credentials from Password Stores: Credentials from Web Browsers (T1555.003) with moderate to high confidence (80%), supported by evidence indicating decryption of stored passwords using stolen symmetric encryption keys, OS Credential Dumping: Security Account Manager (T1003.002) with high confidence (90%), supported by evidence indicating extract credentials from domain controllers using Impacket tools, and Steal Web Session Cookie (T1539) with moderate to high confidence (85%), supported by evidence indicating session hijacking by stealing VPN session cookies. Under the Defense Evasion tactic, the analysis identified Modify Authentication Process: Multi-Factor Authentication (T1556.006) with high confidence (95%), supported by evidence indicating modified authentication files to bypass MFA entirely, Valid Accounts: Default Accounts (T1078.001) with moderate to high confidence (85%), supported by evidence indicating used default credentials for SSL-VPN admin account compromise, and Obfuscated Files or Information (T1027) with moderate to high confidence (70%), supported by evidence indicating ransomware payload employs ChaCha20 and RSA-4096 encryption. Under the Discovery tactic, the analysis identified Account Discovery: Domain Account (T1087.002) with moderate to high confidence (80%), supported by evidence indicating lateral movement via SMB and domain controller access and Network Service Discovery (T1046) with moderate to high confidence (75%), supported by evidence indicating use of Impacket tools (psexec.py, smbclient.py) for lateral movement. Under the Lateral Movement tactic, the analysis identified Remote Services: SMB/Windows Admin Shares (T1021.002) with high confidence (90%), supported by evidence indicating lateral movement via SMB using Impacket tools and Use Alternate Authentication Material: Pass the Hash (T1550.002) with moderate to high confidence (70%), supported by evidence indicating credential extraction from domain controllers (implied). Under the Collection tactic, the analysis identified Data from Local System (T1005) with high confidence (90%), supported by evidence indicating data exfiltration targeting Microsoft OneDrive and SharePoint and Data from Information Repositories: SharePoint (T1213.002) with high confidence (90%), supported by evidence indicating exfiltration of data from Microsoft OneDrive and SharePoint. Under the Command and Control tactic, the analysis identified Application Layer Protocol: Web Protocols (T1071.001) with moderate to high confidence (80%), supported by evidence indicating data exfiltration via FileZilla and RClone (implied C2) and Ingress Tool Transfer (T1105) with moderate to high confidence (75%), supported by evidence indicating use of custom tool (main.exe) for data exfiltration. Under the Exfiltration tactic, the analysis identified Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) with high confidence (95%), supported by evidence indicating data exfiltrated to Mega using 7-Zip, RClone, and FileZilla and Exfiltration Over C2 Channel (T1041) with moderate to high confidence (80%), supported by evidence indicating tens of terabytes of data transferred to attacker-controlled storage. Under the Impact tactic, the analysis identified Data Encrypted for Impact (T1486) with high confidence (95%), supported by evidence indicating ransomware payload appends .ENCRT extension to locked files and Data Destruction (T1485) with moderate confidence (60%), supported by evidence indicating double-extortion tactics (threat to leak or sell data). These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.

Initial Access
Exploit Public-Facing Application (95%)
Valid Accounts: Cloud Accounts (85%)
Phishing: Spearphishing Attachment (30%)
Credential Access
Brute Force: Password Guessing (70%)
Credentials from Password Stores: Credentials from Web Browsers (80%)
OS Credential Dumping: Security Account Manager (90%)
Steal Web Session Cookie (85%)
Defense Evasion
Modify Authentication Process: Multi-Factor Authentication (95%)
Valid Accounts: Default Accounts (85%)
Obfuscated Files or Information (70%)
Discovery
Account Discovery: Domain Account (80%)
Network Service Discovery (75%)
Lateral Movement
Remote Services: SMB/Windows Admin Shares (90%)
Use Alternate Authentication Material: Pass the Hash (70%)
Collection
Data from Local System (90%)
Data from Information Repositories: SharePoint (90%)
Command and Control
Application Layer Protocol: Web Protocols (80%)
Ingress Tool Transfer (75%)
Exfiltration
Exfiltration Over Web Service: Exfiltration to Cloud Storage (95%)
Exfiltration Over C2 Channel (80%)
Impact
Data Encrypted for Impact (95%)
Data Destruction (60%)

Sources & References