7 Sources
[1]
AWS says 600+ FortiGate firewalls hit in AI-augmented attack
Off-the-shelf tools helped Russian-speaking cybercrime group run riot Cybercriminals armed with off-the-shelf generative AI tools compromised more than 600 internet-exposed FortiGate firewalls across 55 countries in just over a month, according to a new incident report from AWS. The campaign,
[2]
Hackers Used AI to Breach 600 Firewalls in Weeks, Amazon says
Over the last five weeks, a limited number of hackers broke into more than 600 firewalls across dozens of countries with the help of widely available artificial intelligence tools, according to security research from Amazon.com Inc. The small group of hackers - or possibly just one person - used
[3]
Amazon: AI-assisted hacker breached 600 FortiGate firewalls in 5 weeks
Amazon is warning that a Russian-speaking hacker used multiple generative AI services as part of a campaign that breached more than 600 FortiGate firewalls across 55 countries in five weeks. A new report by CJ Moses, CISO of Amazon Integrated Security, says that the hacking campaign occurred
[4]
Russian hacker uses multiple AI tools to break hundreds of firewalls
* Russian hacker brute-forced FortiGate firewalls using weak credentials * AI-generated scripts enabled data parsing, reconnaissance, and lateral movement * The campaign targeted Veeam servers; attacker abandoned hardened systems A Russian hacker was recently seen brute-forcing their way into
[5]
Hacker used commercial AI to breach 600 firewalls, AWS reveals
AWS describes the campaign as an 'AI-powered assembly line for cybercrime'. Commercial AI services are lowering the technical barrier needed to commit cybercrimes, and Amazon warns that this trend will continue. Amazon Web Services (AWS) says it has observed what it describes as a
[6]
AI Let 'Unsophisticated' Hacker Breach 600 FortiGate Firewalls, AWS Says, As AI Lowers 'The Barrier' For Threat Actors
"[AI] is making certain types of attacks more accessible to less sophisticated actors who can now leverage AI to enhance their capabilities and operate at greater scale," said Amazon's CSO Stephen Schmidt, regarding AWS' report that found over 600 Fortinet FortiGate firewalls were
[7]
Amazon AI Cyberattack Hits 600 FortiGate Devices
The attackers did not exploit advanced vulnerabilities. Instead, they targeted exposed management ports and weak, single-factor authentication settings. The report shows how is reshaping threat operations. Commercially available AI tools were used to generate attack scripts, automate
Share
Copy Link
A Russian-speaking cybercriminal armed with commercial generative AI tools compromised more than 600 FortiGate firewalls across 55 countries between January and February 2026. AWS security researchers discovered the campaign relied on AI-generated scripts and automated attacks targeting weak credentials rather than sophisticated exploits, demonstrating how AI is lowering the barrier for cybercrime.
A financially motivated Russian-speaking threat actor breached over 600 firewalls across 55 countries in just five weeks, relying heavily on commercial generative AI tools to automate and scale what would traditionally require a larger, more skilled team
1
2
. According to an incident report from AWS, the AI cyberattack campaign ran from January 11 to February 18, 2026, targeting FortiGate firewalls through exposed management interfaces and weak security credentials rather than sophisticated zero-day vulnerabilities3
. CJ Moses, CISO at Amazon, described the operation as an "AI-powered assembly line for cybercrime, helping less skilled workers produce at scale"5
. The volume and variety of custom tooling observed would typically indicate a well-resourced development team, yet investigators believe a single actor or very small group generated the entire toolkit through AI-assisted development1
.
Source: Analytics Insight
The campaign began with systematic scanning for FortiGate management interfaces exposed to the internet on ports 443, 8443, 10443, and 4443
3
4
. Rather than exploiting vulnerabilities, the attacker deployed brute-force attacks using commonly reused or weak credentials protected only by single-factor authentication1
5
. Once inside, the attackers extracted configuration files containing SSL-VPN user credentials with recoverable passwords, administrative credentials, network topology details, and firewall rules3
. These configuration files were then parsed and decrypted using AI-generated attack scripts written in Python and Go, enabling rapid lateral movement within networks3
4
. The compromised devices were spread across South Asia, Latin America, the Caribbean, West Africa, Northern Europe, and Southeast Asia, suggesting opportunistic targeting rather than sector-specific focus2
3
.
Source: Silicon Republic
Analysis of the source code revealed clear indicators of AI-assisted development, including redundant comments that merely restate function names, simplistic architecture with disproportionate investment in formatting over functionality, and naive JSON parsing via string matching rather than proper deserialization
3
4
. While functional for the threat actor's specific use case, the tooling lacked robustness and failed under edge cases—characteristics typical of AI-generated code used without significant refinement3
. The attacker utilized at least two large language model providers throughout the campaign to generate reconnaissance tools, develop credential extraction utilities, and create operational documentation3
. In one instance, the actor submitted a full internal victim network topology, including IP addresses, hostnames, credentials, and known services, to an AI service and requested help spreading further into the network3
. This demonstrates how generative AI tools are fundamentally changing the threat landscape by enabling less sophisticated actors to conduct operations previously reserved for well-resourced teams.
Source: BleepingComputer
Related Stories
Following VPN access to victim networks, the threat actor deployed custom reconnaissance tools to analyze routing tables, classify networks by size, run port scans, identify SMB hosts and domain controllers, and search for HTTP services
3
. The campaign specifically targeted Active Directory environments, using tools like Meterpreter and mimikatz to conduct DCSync attacks against Windows domain controllers and extract NTLM password hashes3
. Notably, the attacker showed particular interest in Veeam Backup & Replication servers, deploying custom PowerShell scripts and compiled credential-extraction tools while attempting to exploit known Veeam vulnerabilities including CVE-2023-27532 and CVE-2024-407113
. Security experts note that threat actors typically target backup infrastructure before deploying ransomware to prevent restoration of encrypted files from backups, suggesting the campaign was setting up for ransomware attacks2
3
. When encountering more hardened security environments, the attacker simply moved on to easier targets rather than persisting, reinforcing that volume rather than technical sophistication was the winning strategy1
2
.AWS emphasizes that basic cybersecurity hygiene measures would have shut down much of the activity before it gained traction
1
. Recommendations include ensuring FortiGate management interfaces are not exposed to the internet, enforcing multi-factor authentication, implementing unique complex passwords for all accounts, and ensuring VPN passwords differ from Active Directory credentials3
5
. Moses warns that organizations should anticipate AI-augmented threat activity will continue to grow in volume from both skilled and unskilled adversaries2
. The findings arrive weeks after Google warned that criminals are increasingly integrating generative AI directly into their operations, including abuse of its Gemini AI chatbot for tasks ranging from reconnaissance and target profiling to phishing and malware development1
3
. Last year, Anthropic reported that a hacker leveraged its technology as part of a vast cybercrime scheme impacting at least 17 organizations, marking what was then an unprecedented instance of attackers weaponizing commercial artificial intelligence tools on a widespread basis2
.Summarized by
Navi
[1]
[3]
[5]
02 Sept 2026•Technology

10 Sept 2026•Technology

28 Jul 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
