TheHatman and FortiBleed Campaigns Highlight Rising Threat of Large-Scale Credential Attacks

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Recent reports highlight a concerning trend in cybersecurity, with the emergence of large-scale credential attacks exemplified by the activities of threat actors known as TheHatman and the FortiBleed campaign. According to reporting by Unit 42, these attacks leverage previously leaked credentials to gain unauthorized access to various services, marking a shift in tactics where cybercriminals prefer to log in rather than break in.

TheHatman and FortiBleed Campaigns

TheHatman Attack

Between August 1 and August 17, 2026, an individual using the alias “TheHatman” claimed to have stolen a significant volume of credentials from organizations’ Microsoft Entra tenants. This actor reportedly offered to sell sensitive employee information across multiple forums. While TheHatman asserts that the data was obtained through compromised credentials, the specific method of intrusion remains unverified.

FortiBleed Campaign

In June 2026, a large-scale password spraying campaign targeting Fortinet devices, dubbed the FortiBleed campaign, was disclosed. This campaign also included attempts against MSSQL and Sophos devices. Attackers utilized a curated password list, likely compiled from previous breaches, to execute password spraying against internet-exposed services. Once credentials were obtained, they were added to the attackers’ password list for future exploitation.

Mitigation Recommendations

Unit 42 recommends several defensive measures to mitigate the risks associated with these credential attacks. Organizations are advised to audit remote access logs for suspicious activity, particularly focusing on successful logins following a high volume of password failures. Additionally, implementing strong multi-factor authentication (MFA) and adopting a zero trust architecture can significantly enhance security posture.

As the threat landscape evolves, continuous monitoring and proactive measures are essential to defend against identity-based attacks. The Unit 42 Incident Response team is available to assist organizations in assessing their risk and responding to potential compromises.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...