AI-augmented threat actor accesses FortiGate devices at scale
Security Blog
This article details how a Russian-speaking financially motivated threat actor used commercial AI services to compromise over 600 FortiGate devices across 55+ countries from January-February 2026.
- Threat actor exploited exposed management ports and weak credentials, not FortiGate vulnerabilities
- Used multiple commercial LLM services for attack planning, tool development, and operational assistance
- Deployed AI-generated reconnaissance tools and custom scripts across victim networks
- Conducted post-exploitation activities: Active Directory compromise, credential harvesting, backup infrastructure targeting
- Failed against hardened environments; moved to softer targets rather than persisting
- Low-to-medium baseline technical skill significantly augmented by AI dependency
- Organizations should audit FortiGate appliances, enforce MFA, implement credential hygiene, and harden backup infrastructure
This campaign demonstrates how commercial AI lowers barriers to entry for unsophisticated threat actors, enabling operational scale previously requiring larger teams. Strong security fundamentals remain the most effective defense.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2026
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.