logo

AI-augmented threat actor accesses FortiGate devices at scale

ID: 70ce56ac-7d84-52c8-93e6-2d24cd60128f

STIX ID: report--70ce56ac-7d84-52c8-93e6-2d24cd60128f

Feed Name: AWS Security Blog

Threat Score
75/100

Date Published: 2026-02-20

Date Updated: 2026-04-27

Author: CJ Moses

...
...

Amazon Threat Intelligence observed a financially motivated, Russian-speaking actor using multiple commercial generative AI services to compromise over 600 FortiGate appliances across 55+ countries (Jan 11–Feb 18, 2026) by scanning exposed management ports and abusing weak single-factor credentials; the actor extracted full device configurations and Active Directory credential databases, used AI-generated reconnaissance and post-exploitation tooling, targeted Veeam backup servers, and hosted additional operational files on public infrastructure; recommended defenses include removing internet-exposed management interfaces, enforcing MFA, rotating credentials, patching backup systems, and monitoring for anomalous AD replication and VPN activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.