/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Dutch agencies: 20K+ FortiGate systems were hacked in a Chinese cyber-espionage campaign in 2022 and 2023, at least two months before FortiGate noted the flaw

Sergiu Gatlan / BleepingComputer :

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

The disclosure broadens a Dutch account of a Fortinet vulnerability used against the Dutch Ministry of Defence into evidence of a much wider campaign affecting FortiGate users.

It also fits earlier government reporting that China-linked groups exploited internet-facing products from multiple vendors, including F5, Citrix, Pulse Secure, and Microsoft Exchange. The significance is the reported gap between exploitation and identification of the FortiGate flaw.

First-order effects

  • Organizations operating affected FortiGate systems must treat the reported 2022–23 activity as a potential historical intrusion, not solely a patching issue, and review exposure and access for that period.
  • Dutch agencies’ account puts FortiGate vulnerability discovery and customer notification under sharper scrutiny because the campaign reportedly preceded identification by at least two months.

Second-order effects

  • Security teams are likely to give greater priority to monitoring and incident-response coverage for perimeter devices, since patch status alone cannot resolve compromise that occurred before a vulnerability was known.
  • Other network-edge vendors and their customers face renewed pressure to detect abuse faster; prior reporting on China-linked targeting of Pulse Secure devices shows the pattern is not confined to one product line.

Third-order effects

  • If repeated across vendors, this points to perimeter appliances becoming a durable intelligence-collection layer: attackers can gain broad access before defenders have a public indicator to act on.
  • The likely systemic response is greater reliance on coordinated government-vendor disclosure and post-disclosure compromise assessment, rather than treating vulnerability notices as purely forward-looking patch events.

The trend: State-linked espionage campaigns are increasingly turning widely deployed network-edge products into scalable entry points, raising the value of detection and retrospective investigation alongside patching.

Discussion

  • @arekfurt @arekfurt on x
    The PRC exploited 14,000 Fortigate devices before the vulnerability in question here was even announced. Just let that sink in. Mass intrusion campaigns by state actors abusing either perimeter 0days or supply chain backdoors have become reality.
  • @arekfurt @arekfurt on x
    In the incidents so far, relatively few targets (compared to the number initially compromised) have promptly seen follow-up malware deployment + follow-on intrusion activities. But...
  • @arekfurt @arekfurt on x
    But one must suspect said state actors could be investing in capabilities to better enable practical abuse of footholds at larger scale.
  • @jackson5_sec @jackson5_sec on x
    china wrecking you. ur corp/consult red team that can barely handle 3 shells. imagine having 20k at once in 1 day and trying to decide what to go after in a scaled way. GG https://www.bleepingcomputer.com/ ...
  • r/hacking r on reddit
    China state hackers infected 20,000 Fortinet VPNs, Dutch spy service says
  • r/technology r on reddit
    China state hackers infected 20,000 Fortinet VPNs, Dutch spy service says
  • r/privacy r on reddit
    Chinese hackers breached 20,000 FortiGate systems worldwide