TheHatman and FortiBleed Campaigns Highlight Rising Threat of Large-Scale Credential Attacks

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Recent reports highlight a concerning trend in cybersecurity, with the emergence of large-scale credential attacks exemplified by the activities of threat actors known as TheHatman and the FortiBleed campaign. According to reporting by Unit 42, these attacks leverage previously leaked credentials to gain unauthorized access to various services, marking a shift in tactics where cybercriminals prefer to log in rather than break in.

TheHatman and FortiBleed Campaigns

TheHatman Attack

Between August 1 and August 17, 2026, an individual using the alias “TheHatman” claimed to have stolen a significant volume of credentials from organizations’ Microsoft Entra tenants. This actor reportedly offered to sell sensitive employee information across multiple forums. While TheHatman asserts that the data was obtained through compromised credentials, the specific method of intrusion remains unverified.

FortiBleed Campaign

In June 2026, a large-scale password spraying campaign targeting Fortinet devices, dubbed the FortiBleed campaign, was disclosed. This campaign also included attempts against MSSQL and Sophos devices. Attackers utilized a curated password list, likely compiled from previous breaches, to execute password spraying against internet-exposed services. Once credentials were obtained, they were added to the attackers’ password list for future exploitation.

Mitigation Recommendations

Unit 42 recommends several defensive measures to mitigate the risks associated with these credential attacks. Organizations are advised to audit remote access logs for suspicious activity, particularly focusing on successful logins following a high volume of password failures. Additionally, implementing strong multi-factor authentication (MFA) and adopting a zero trust architecture can significantly enhance security posture.

As the threat landscape evolves, continuous monitoring and proactive measures are essential to defend against identity-based attacks. The Unit 42 Incident Response team is available to assist organizations in assessing their risk and responding to potential compromises.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

FQ-42 Vengeance unmanned fighter aircraft displayed at AFA 2026

The FQ-42 Vengeance unmanned fighter aircraft, developed by General Atomics, was prominently displayed at the Air, Space and Cyber conference on September 14, 2026....

Meta’s AI Assistant Muse Exposed by Zero-Day Vulnerability, Prompting Amazon to Block Access

Meta's new AI assistant, Muse, has come under scrutiny following the discovery of a zero-day vulnerability that allows locally run applications and terminal commands...

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...