Belsen Group is a cybercriminal initial-access and data-leak actor known for publishing and monetizing access derived from compromised Fortinet FortiGate devices. The group gained prominence in early 2025 after leaking configuration data and passwords from more than 15,000 Fortinet devices. Reporting links that dataset to older compromise activity dating to 2022, with the data later repackaged and released publicly. The actor subsequently shifted from publishing exposed device data to brokering direct corporate access, including advertised remote code execution access into victim environments. The group’s activity centers on exploiting or otherwise obtaining FortiGate configuration data and turning that access into a commercial product for other criminals. This places Belsen Group in the initial-access broker ecosystem rather than a pure ransomware operator. Observed tradecraft includes compromise of internet-exposed edge devices, theft and publication of credentials and configuration material, and resale of validated enterprise access. Belsen Group has been associated with high-value targeting, including major enterprises and at least one large energy-sector organization in North Africa. Belsen Group is distinct from the later FortiBleed activity affecting a much larger population of Fortinet devices. Multiple analyses found that the FortiBleed dataset largely did not overlap with the Belsen Group leak, indicating a different source of compromise. High-confidence reporting supports Belsen Group’s role in the earlier 15,000-device Fortinet leak and in monetizing the resulting access, but does not firmly attribute the group to a specific state sponsor or country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a previously known group that published Fortinet-related data in 2025; in this reference it is mentioned for comparison to show the newly found FortiBleed database likely came from a different source.
Previously associated with a 2025 leak of Fortinet device data covering 15,000 devices, described here as old data from a 2022 zero-day.
Linked in the content to the theft/leak of configuration data from 15,000 Fortinet firewalls, which may have supported broader compromise activity against exposed Fortinet devices.
Previously associated with a leak of Fortinet device data affecting 15,000 devices, based on older data from a 2022 zero-day.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.