Recently, a list allegedly involving 96 domestic companies, referred to as 'Internet Access,' has been circulating online, with rumors suggesting a possible connection to FortiBleed-related cyberattacks. This has raised concerns among businesses about network equipment security, credential leaks, and potential internal system breaches.

In response, Dr. Zhang Guanghong, a cybersecurity expert with nearly 30 years of practical experience and involvement in national critical infrastructure and corporate cybersecurity defense, stated that the appearance of company names or domains on the dark web does not necessarily mean their systems have been compromised. However, he urges organizations to treat such intelligence as a high-priority risk signal and promptly initiate asset inventory and security audits.

According to Dr. Zhang, his technical team conducted offline structural analysis of the files circulating online. The analysis revealed that the content primarily lists corporate domains and scale information, with no direct technical evidence of successful intrusion—such as IP addresses, login credentials, session tokens, internal network screenshots, or data leak samples. From the perspective of cybersecurity industry operations, such data may serve as a commercial catalog used by 'initial access brokers' to showcase or sell potential access rights. However, whether these actors possess actual, effective intrusion capabilities requires further technical forensics and verification.

He explained that the presence of company names in dark web intelligence could stem from historical domains, past maintenance records, or residual data from previous incidents, and does not necessarily indicate that the internal network has been penetrated or that data has been leaked. Nevertheless, companies should still conduct thorough checks on relevant domains, external services, VPN accounts, and device logs to identify any signs of abnormal logins, unauthorized access, or credential misuse.

Regarding the public focus on specific cybersecurity equipment brands, Dr. Zhang emphasized the need to return to a holistic view of cybersecurity architecture and management mechanisms. Boundary devices such as firewalls, VPNs, load balancers, and routers are constantly exposed to public networks, making them prime targets for automated scanning, brute-force attacks, and credential-based attacks. All security products face risks such as software vulnerabilities, zero-day exploits, or misconfigurations, and it is inappropriate to discredit an entire product or brand based on a single incident.

Dr. Zhang pointed out that corporate cybersecurity incidents may also stem from poor 'cyber hygiene' practices, such as leaked legacy configuration files, failure to enable multi-factor authentication (MFA), inactive default accounts, long-unused passwords, or management interfaces directly exposed to the external internet. Beyond continuous patching, companies should establish robust account and credential management systems and gradually shift from perimeter-based defense to zero-trust and defense-in-depth architectures.

He stressed that companies should neither panic nor ignore such dark web intelligence. Instead, they should objectively assess risks through asset inventory, log analysis, vulnerability remediation, and continuous monitoring, while integrating threat intelligence and collaborative defense mechanisms to enhance overall digital resilience.

FACT BOX

  • Source: PR Times
  • Category: News