Amazon Threat Intelligence reported a Russian-speaking, financially motivated actor using multiple commercial generative AI services to scale compromise of 600+ Fortinet FortiGate devices across 55+ countries (observed Jan 11–Feb 18, 2026). The campaign did not rely on exploiting FortiGate vulnerabilities; instead it targeted internet-exposed management ports protected by weak credentials and single-factor authentication. Post-compromise activity included attempts to access Active Directory environments, extract credential databases, and target backup infrastructure, behavior consistent with preparation for ransomware or other monetization, while noting the actor struggled more in hardened environments. AWS stated its infrastructure was not observed to be involved.
An SC Media commentary cautioned that many “AI-driven” labels applied to FortiGate-related campaigns may be overstated, arguing public evidence more strongly supports automation (scripted scanning and credential attacks) rather than adaptive, decision-making AI. The piece emphasizes that conflating automation with AI can mislead defenders about what to prioritize, even as the AWS reporting highlights how readily available GenAI tools can lower the barrier for less-skilled actors to operationalize known techniques at greater scale.

Map this exposure pattern across your cloud, code, and identities.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-23, follow-on reporting distinguished the AI-augmented credential-abuse campaign from a separate January wave that exploited a patched FortiGate authentication-bypass vulnerability. The clarification indicated the overlapping FortiGate activity reflected multiple concurrent threats rather than one continuous operation.
By 2026-02-23, reporting on Amazon's investigation said the company had disrupted the campaign, shared indicators and intelligence with partners, and coordinated with industry to reduce the actor's effectiveness. This marked the first explicit public indication of active defensive coordination beyond the initial disclosure.
On 2026-02-20, Amazon Threat Intelligence publicly reported the campaign, assessing that the low-to-medium skill actor used multiple commercial generative AI services to amplify attack planning, tooling, and operations. Amazon also stated AWS infrastructure was not involved and recommended removing management exposure, enabling MFA, improving credential hygiene, segmentation, and patching.
Amazon said the observed FortiGate campaign ran from 2026-01-11 through 2026-02-18. By the end of that period, the operation had reached global scale but still showed frequent failures against patched or hardened environments.
Between mid-January and mid-February 2026, the actor compromised more than 600 FortiGate devices across 55+ countries, stole device configuration files, and harvested credentials and network details. Using that access, the actor attempted post-exploitation actions including Active Directory compromise, credential dumping, lateral movement, and targeting Veeam Backup & Replication systems as a likely precursor to ransomware.
On 2026-01-11, a Russian-speaking, financially motivated threat actor began a large-scale campaign against internet-exposed FortiGate management interfaces. The activity relied on scanning exposed ports and abusing weak or reused single-factor credentials rather than exploiting FortiGate vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
16 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcecsoonline.com
Open sourceaws.amazon.com
Open sourcescworld.com
Open sourceaws-news.com
Open sourcenoise.getoto.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.