Full Breakdown
AI-Augmented Cyberattacks Target FortiGate Firewalls Worldwide
2/23/2026, 11:42:58 PM
Overview of the Cyberattack Campaign
Between January 11 and February 18, 2026, a financially motivated, Russian-speaking threat actor compromised over 600 Fortinet FortiGate firewalls across more than 55 countries. This campaign, reported by Amazon Web Services (AWS), marks a significant evolution in cybercrime, as it utilized multiple commercial generative AI (GenAI) services to automate and scale attacks without exploiting technical vulnerabilities. Instead, the attackers targeted exposed management interfaces and weak single-factor authentication credentials, demonstrating how AI can empower less skilled individuals to conduct sophisticated cyber operations.
Attack Methodology and Tools
The threat actor employed AI tools to develop custom scripts for reconnaissance and exploitation. They systematically scanned for internet-exposed management ports and executed credential-based attacks using commonly reused passwords. Once inside, they extracted sensitive configuration files containing VPN credentials, administrative passwords, and network topology data. The attackers utilized AI-assisted Python and Go scripts to parse and decrypt these configurations, facilitating lateral movement within victim networks and attempts to access backup systems, which could indicate plans for ransomware attacks.
The operational notes from the attackers revealed a reliance on AI-generated code, characterized by simplistic architecture and redundant comments, which often lacked robustness against edge cases. Despite their limited technical skills, the attackers managed to automate various phases of their operations, including network mapping and vulnerability scanning, allowing them to shift focus to softer targets when encountering stronger defenses.
Implications of AI in Cybercrime
Experts have noted that this incident signifies a turning point in the cyber threat landscape, where AI tools lower the barriers to entry for cybercriminals. Damon Small, a board member at Xcape, Inc., remarked that the campaign represents an "automated assembly-line" approach to cyberattacks, enabling individuals with minimal expertise to conduct large-scale intrusions. Jacob Krell, senior director at Suzu Labs, emphasized that the use of commercial AI has democratized offensive cyber capabilities, making them accessible to anyone willing to invest in these technologies.
Recommendations for Organizations
In light of this campaign, AWS has provided several recommendations for organizations using FortiGate appliances to enhance their security posture. These include disabling internet access to management interfaces unless necessary, changing default passwords, implementing multifactor authentication, and regularly reviewing VPN connection logs for unauthorized access. Organizations are also advised to isolate backup infrastructure from main networks to mitigate potential disruptions from cyberattacks.
Conflicting Reports & Gaps
While the AWS report indicates that the threat actor did not exploit any FortiGate vulnerabilities, some experts have pointed out that the campaign's timing coincides with other attacks targeting specific vulnerabilities in FortiGate systems. This raises questions about the overall security landscape and the need for improved perimeter defenses.
Verbatim Quotes
- “This activity is distinguished by the threat actor’s use of multiple commercial GenAI services to implement and scale well-known attack techniques throughout every phase of the operations, despite their limited technical capabilities,” — CJ Moses, Chief Information Security Officer, Amazon Integrated Security
- “Commercial AI has done for cyber offense what the internet did for fraud. It made something that required years of expertise and a skilled team available to anyone willing to subscribe.” — Jacob Krell, Senior Director, Suzu Labs
This incident underscores the growing threat posed by AI-augmented cybercriminals and highlights the urgent need for organizations to bolster their cybersecurity measures against evolving tactics.
