logo

AWS says more than 600 FortiGate firewalls hit in AI-augmented campaign

ID: 85d2c667-45c9-59bc-a750-eab02371a622

STIX ID: report--85d2c667-45c9-59bc-a750-eab02371a622

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-02-23

Date Updated: 2026-04-26

Author: Carly Page

...
...

Cybercriminals leveraged commercial generative AI to automate large-scale scanning and credential-guessing against internet-exposed FortiGate management interfaces, compromising more than 600 devices across 55 countries in roughly one month; attackers exfiltrated configuration files (including admin and VPN credentials), pursued lateral movement into Active Directory and backup systems, and favored high-volume opportunistic targeting. AWS attributes the activity to a financially motivated Russian-speaking group and emphasizes that basic hygiene—removing management interfaces from the public internet, enforcing MFA, and preventing password reuse—would have prevented many of the compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.