Home icon

AI-augmented threat actor accesses FortiGate devices at scale

Security Blog



This article details how a Russian-speaking financially motivated threat actor used commercial AI services to compromise over 600 FortiGate devices across 55+ countries from January-February 2026.

  • Threat actor exploited exposed management ports and weak credentials, not FortiGate vulnerabilities
  • Used multiple commercial LLM services for attack planning, tool development, and operational assistance
  • Deployed AI-generated reconnaissance tools and custom scripts across victim networks
  • Conducted post-exploitation activities: Active Directory compromise, credential harvesting, backup infrastructure targeting
  • Failed against hardened environments; moved to softer targets rather than persisting
  • Low-to-medium baseline technical skill significantly augmented by AI dependency
  • Organizations should audit FortiGate appliances, enforce MFA, implement credential hygiene, and harden backup infrastructure

This campaign demonstrates how commercial AI lowers barriers to entry for unsophisticated threat actors, enabling operational scale previously requiring larger teams. Strong security fundamentals remain the most effective defense.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Feb 16
2026
Building an AI-powered defense-in-depth security architecture for serverless microservices
Apr 7
2026
Building AI defenses at scale: Before the threats emerge
May 13
2026
Securing AI agents: How AWS and Cisco AI Defense scale MCP and A2A deployments
Jun 18
2025
Accelerate threat modeling with generative AI

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.