Dutch agencies: 20K+ FortiGate systems were hacked in a Chinese cyber-espionage campaign in 2022 and 2023, at least two months before FortiGate noted the flaw
Sergiu Gatlan / BleepingComputer :
Context & Ripple Effects
The disclosure broadens a Dutch account of a Fortinet vulnerability used against the Dutch Ministry of Defence into evidence of a much wider campaign affecting FortiGate users.
It also fits earlier government reporting that China-linked groups exploited internet-facing products from multiple vendors, including F5, Citrix, Pulse Secure, and Microsoft Exchange. The significance is the reported gap between exploitation and identification of the FortiGate flaw.
First-order effects
- Organizations operating affected FortiGate systems must treat the reported 2022–23 activity as a potential historical intrusion, not solely a patching issue, and review exposure and access for that period.
- Dutch agencies’ account puts FortiGate vulnerability discovery and customer notification under sharper scrutiny because the campaign reportedly preceded identification by at least two months.
Second-order effects
- Security teams are likely to give greater priority to monitoring and incident-response coverage for perimeter devices, since patch status alone cannot resolve compromise that occurred before a vulnerability was known.
- Other network-edge vendors and their customers face renewed pressure to detect abuse faster; prior reporting on China-linked targeting of Pulse Secure devices shows the pattern is not confined to one product line.
Third-order effects
- If repeated across vendors, this points to perimeter appliances becoming a durable intelligence-collection layer: attackers can gain broad access before defenders have a public indicator to act on.
- The likely systemic response is greater reliance on coordinated government-vendor disclosure and post-disclosure compromise assessment, rather than treating vulnerability notices as purely forward-looking patch events.
The trend: State-linked espionage campaigns are increasingly turning widely deployed network-edge products into scalable entry points, raising the value of detection and retrospective investigation alongside patching.