TheHatman and FortiBleed Campaigns Highlight Rising Threat of Large-Scale Credential Attacks

Published:

spot_img

Recent reports highlight a concerning trend in cybersecurity, with the emergence of large-scale credential attacks exemplified by the activities of threat actors known as TheHatman and the FortiBleed campaign. According to reporting by Unit 42, these attacks leverage previously leaked credentials to gain unauthorized access to various services, marking a shift in tactics where cybercriminals prefer to log in rather than break in.

TheHatman Attack

Between August 1 and August 17, 2026, an individual using the alias “TheHatman” claimed to have stolen a significant volume of credentials from organizations’ Microsoft Entra tenants. This actor reportedly offered to sell sensitive employee information across multiple forums. While TheHatman asserts that the data was obtained through compromised credentials, the specific method of intrusion remains unverified.

FortiBleed Campaign

In June 2026, a large-scale password spraying campaign targeting Fortinet devices, dubbed the FortiBleed campaign, was disclosed. This campaign also included attempts against MSSQL and Sophos devices. Attackers utilized a curated password list, likely compiled from previous breaches, to execute password spraying against internet-exposed services. Once credentials were obtained, they were added to the attackers’ password list for future exploitation.

Mitigation Recommendations

Unit 42 recommends several defensive measures to mitigate the risks associated with these credential attacks. Organizations are advised to audit remote access logs for suspicious activity, particularly focusing on successful logins following a high volume of password failures. Additionally, implementing strong multi-factor authentication (MFA) and adopting a zero trust architecture can significantly enhance security posture.

As the threat landscape evolves, continuous monitoring and proactive measures are essential to defend against identity-based attacks. The Unit 42 Incident Response team is available to assist organizations in assessing their risk and responding to potential compromises.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

Red Hat OpenShift Container Platform 4.22.10 includes important security update

Red Hat has announced the release of OpenShift Container Platform version 4.22.10, which includes critical updates aimed at addressing various bugs and enhancing system...

CrowdStrike Enhances AI Detection Triage with Reasoning-Enabled Models

In the realm of cybersecurity, the ability to discern genuine threats from benign...

Core42 Enhances AI Deployment for UAE Government Services with Secure Infrastructure

Core42 Enhances AI Deployment for UAE Government Services with Secure Infrastructure Core42 is advancing the deployment of artificial intelligence (AI) within UAE government services by...

Attackers Exploit MLflow SSRF Vulnerability to Exfiltrate Cloud Credentials

Two critical vulnerabilities affecting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, a web-based SCADA/HMI software, are currently being exploited by attackers. Reports...