TheHatman and FortiBleed Campaigns Highlight Rising Threat of Large-Scale Credential Attacks

Published:

spot_img

Recent reports highlight a concerning trend in cybersecurity, with the emergence of large-scale credential attacks exemplified by the activities of threat actors known as TheHatman and the FortiBleed campaign. According to reporting by Unit 42, these attacks leverage previously leaked credentials to gain unauthorized access to various services, marking a shift in tactics where cybercriminals prefer to log in rather than break in.

TheHatman and FortiBleed Campaigns

TheHatman Attack

Between August 1 and August 17, 2026, an individual using the alias “TheHatman” claimed to have stolen a significant volume of credentials from organizations’ Microsoft Entra tenants. This actor reportedly offered to sell sensitive employee information across multiple forums. While TheHatman asserts that the data was obtained through compromised credentials, the specific method of intrusion remains unverified.

FortiBleed Campaign

In June 2026, a large-scale password spraying campaign targeting Fortinet devices, dubbed the FortiBleed campaign, was disclosed. This campaign also included attempts against MSSQL and Sophos devices. Attackers utilized a curated password list, likely compiled from previous breaches, to execute password spraying against internet-exposed services. Once credentials were obtained, they were added to the attackers’ password list for future exploitation.

Mitigation Recommendations

Unit 42 recommends several defensive measures to mitigate the risks associated with these credential attacks. Organizations are advised to audit remote access logs for suspicious activity, particularly focusing on successful logins following a high volume of password failures. Additionally, implementing strong multi-factor authentication (MFA) and adopting a zero trust architecture can significantly enhance security posture.

As the threat landscape evolves, continuous monitoring and proactive measures are essential to defend against identity-based attacks. The Unit 42 Incident Response team is available to assist organizations in assessing their risk and responding to potential compromises.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

Critical CVE-2026-19490 Authentication Bypass Vulnerability Discovered in Citrix NetScaler ADC and Gateway

Critical Authentication Bypass Vulnerability in Citrix NetScaler ADC and Gateway On August 19, 2026, a significant security advisory was issued regarding CVE-2026-19490, an authentication bypass...

Microsoft Recognized as a Leader in Frost Radar for Cloud Workload Protection Platforms 2026

As organizations increasingly migrate to cloud-native architectures, the need for robust cloud workload protection has never been more critical. A recent report from Frost...

Cloudflare Workers Vulnerability Allows JWT Leakage at 12 Bits Per Second

Cybersecurity researchers have revealed a significant vulnerability in Cloudflare Workers, detailing a remote Spectre attack that can leak a JSON Web Token (JWT) from...

OpenAI Halts Reinforcement Learning Training to Enhance Safeguards Against AI Misbehavior

OpenAI has announced a two-week pause in its reinforcement learning (RL) training for its latest artificial intelligence (AI) models to enhance safeguards and monitoring...