At least 270 Belgian organisations hit by ongoing Russian cyber attack
A large-scale Russian cyber campaign is targeting Belgian organisations through security firm Fortinet. 110 firewalls remain accessible to the attackers.

At least 270 Belgian organisations hit by ongoing Russian cyber attack
At least 270 Belgian organisations have been affected by a Russian cyber campaign that began in February. These include local authorities, law firms and schools. La Libre reports that the attack is still ongoing.
The cyber incident, known as "FortiBleed", is considered one of the largest ever targeting a security solutions provider. More than 110 million access credentials were intercepted, putting more than 75,000 firewalls at risk.
The attackers, linked to a Russian group, exploited Fortinet's partner portal. Through this platform, IT service providers gain access to their customers' systems. The hackers stole the login credentials of thousands of partners, allowing them to breach not just one organisation, but an entire chain of customer networks.
"This operation is distinguished by an unprecedented level of organisation, coordination and scale," warned Belgian cybersecurity firm Secutec. "As a result, the impact simultaneously affects multiple sectors and smaller organisations have also been affected."
The hackers gained their access through "brute force" attacks, in which large numbers of username-password combinations are automatically tested. They then installed spyware. The aim is to steal sensitive information and subsequently extort the affected organisations, or sell their data on the dark web.
According to Secutec CEO Geert Baudewijns, various organisations worldwide have already suffered serious data exfiltration. In Belgium, 110 firewalls belonging to the 270 affected organisations remain accessible via the internet using the intercepted login credentials. Moreover, the hackers created new accounts on at least 45 systems themselves to maintain their access. These access points are being prepared for sale on the dark web.
The Belgian Centre for Cybersecurity (CCB) was informed. Secutec and SOCRadar are urging organisations using Fortinet solutions to update their systems, enable multi-factor authentication and review access and user accounts. "A single weak link can simultaneously grant access to hundreds of organisations," Secutec warned.
Source: La Libre