Skip to content

Broker Advertises Super Admin Access to Golden Tulip Bahrain FortiGate Firewall

Access Listing Bahrain flagBahrain Hospitality / Hotel Access for Sale

Broker Advertises Super Admin Access to Golden Tulip Bahrain FortiGate Firewall

A seller posting as Roiese is offering what they describe as full administrative access to the FortiGate firewall and network security environment of Golden Tulip Bahrain, a hotel property in Bahrain. The listing claims super_admin level control across firewall policies, VPN and remote-access configuration, user and group administration, network objects, and API-based management, and enumerates eight administrative accounts said to hold that profile. Five screenshots of the management interface are attached as proof. The post is formatted as a professional risk assessment, including the seller's own severity rating and a profile of the target's revenue and headcount. The claim is unverified.

Access levelSuper admin
Admin accounts8 listed
CountryBahrain flagBahrain
ActorRoiese

Listing details

TargetGolden Tulip Bahrain
CountryBahrain flagBahrain
SectorHospitality / Hotel
ListingAccess for sale, price on request
EnvironmentFortiGate firewall
Evidence5 interface screenshots
Observed
ActorRoiese

!Advertised capabilities

  • Super_admin profile access
  • Firewall policy modification
  • VPN configuration control
  • Remote-access management
  • Administrative account control
  • User & group administration
  • Application-control profiles
  • Network object visibility
  • Security architecture exposure
  • API-based administration

Screenshots

Potential impact

A firewall is not one system among many; it is the boundary everything else sits behind. Super_admin on a FortiGate would expose the internal network layout and allow policy changes, and the ability to create VPN accounts is the part that persists, since credentials issued now survive remediation elsewhere. For a hotel, property management, booking, and payment systems sit inside that perimeter. Edge appliance access is the standard opening move in ransomware intrusions, which is what this listing is realistically sold for. The target is a single franchised property, not the wider brand. The claim is unverified.

iStatus

Unverified

Five management-interface screenshots make this better substantiated than most access listings, though the account is a month old with no standing. Dark Web Informer is not reproducing the administrative usernames enumerated in the post, or the seller's contact channels. The risk-assessment framing is the seller's own marketing. The claim is unverified and Golden Tulip Bahrain has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest