A threat actor has published an advertisement claiming to possess administrator-level access to the FortiGate security infrastructure used by Golden Tulip Bahrain.
According to the underground listing, the claimed access includes administrator accounts, VPN configurations, firewall policies, user groups, and other critical security settings. The advertisement also states that the access is still active and is being offered privately to potential buyers.
At the time of publication, there is no public confirmation from Golden Tulip Bahrain or Fortinet verifying the authenticity of these claims. Therefore, the incident should be treated as an unverified claim rather than a confirmed security breach until additional evidence becomes available.
If such access were genuine, it could provide attackers with extensive control over an organization’s security infrastructure. FortiGate solutions are widely used to protect enterprise networks, manage firewall policies, and provide secure remote access. Administrator-level access could potentially allow threat actors to modify security settings, monitor network activity, establish persistence, or facilitate additional cyberattacks.
Hotels are attractive targets for cybercriminals because they often manage valuable information, including guest names, reservation records, passport information where collected, and payment-related data. A successful compromise of critical infrastructure could expose sensitive information or disrupt business operations, depending on the systems affected.
Security researchers have observed that some cybercriminal groups specialize in obtaining unauthorized access to organizations and then selling that access to ransomware operators or other threat actors. This business model enables attackers to conduct larger and more damaging campaigns without carrying out the initial compromise themselves.
This incident highlights the importance of protecting privileged accounts, continuously monitoring administrative access, implementing strong authentication mechanisms, promptly applying security updates, and maintaining effective incident detection and response capabilities.
Organizations are encouraged to closely monitor trusted security advisories and official statements for any updates regarding this incident. Until independent verification is available, all underground claims should be approached with caution and should not be treated as confirmed facts.
