Recent reports highlight a concerning trend in cybersecurity, with the emergence of large-scale credential attacks exemplified by the activities of threat actors known as TheHatman and the FortiBleed campaign. According to reporting by Unit 42, these attacks leverage previously leaked credentials to gain unauthorized access to various services, marking a shift in tactics where cybercriminals prefer to log in rather than break in.
TheHatman Attack
Between August 1 and August 17, 2026, an individual using the alias “TheHatman” claimed to have stolen a significant volume of credentials from organizations’ Microsoft Entra tenants. This actor reportedly offered to sell sensitive employee information across multiple forums. While TheHatman asserts that the data was obtained through compromised credentials, the specific method of intrusion remains unverified.
FortiBleed Campaign
In June 2026, a large-scale password spraying campaign targeting Fortinet devices, dubbed the FortiBleed campaign, was disclosed. This campaign also included attempts against MSSQL and Sophos devices. Attackers utilized a curated password list, likely compiled from previous breaches, to execute password spraying against internet-exposed services. Once credentials were obtained, they were added to the attackers’ password list for future exploitation.
Mitigation Recommendations
Unit 42 recommends several defensive measures to mitigate the risks associated with these credential attacks. Organizations are advised to audit remote access logs for suspicious activity, particularly focusing on successful logins following a high volume of password failures. Additionally, implementing strong multi-factor authentication (MFA) and adopting a zero trust architecture can significantly enhance security posture.
As the threat landscape evolves, continuous monitoring and proactive measures are essential to defend against identity-based attacks. The Unit 42 Incident Response team is available to assist organizations in assessing their risk and responding to potential compromises.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


