AI News

Amazon Report: GenAI Fuels Massive Breach of 600+ FortiGate Firewalls Worldwide

A new report from Amazon Threat Intelligence has revealed a disturbing evolution in cybercrime: a Russian-speaking threat actor has leveraged commercial generative AI tools to breach over 600 FortiGate firewalls across 55 countries. The campaign, observed between January 11 and February 18, 2026, exemplifies how artificial intelligence is lowering the barrier to entry for attackers, allowing them to scale operations with industrial efficiency.

According to CJ Moses, Chief Information Security Officer at Amazon Integrated Security, the attacker utilized an "AI-powered assembly line" to automate complex tasks, from coding reconnaissance scripts to planning lateral movement. While the threat actor displayed limited technical sophistication, the use of AI acted as a potent force multiplier, enabling them to compromise critical infrastructure without relying on advanced exploits or zero-day vulnerabilities.

The AI-Powered Assembly Line

The Amazon investigation highlights a critical shift in the threat landscape. The adversary, identified as financially motivated rather than state-sponsored, relied heavily on multiple commercial generative AI platforms. These tools were used to generate attack scripts, orchestrate command execution, and even troubleshoot errors during the intrusion process.

Amazon researchers discovered publicly accessible infrastructure managed by the attackers that hosted a trove of AI-generated artifacts. This included source code for custom hacking tools, victim network configurations, and detailed attack plans. The reliance on AI was so heavy that when the primary AI tool was unavailable, the attacker seamlessly switched to a secondary platform to continue operations.

The custom reconnaissance tools, written in both Go and Python, bore distinct hallmarks of AI generation. Amazon's analysis of the source code revealed "redundant comments that merely restate function names, simplistic architecture with disproportionate investment in formatting over functionality, and naive JSON parsing." These characteristics suggest that the actor lacked the coding prowess to build these tools manually but successfully prompted an AI model to build them to specification.

Technical Analysis: Efficiency Over Sophistication

Contrary to fears of AI developing novel zero-day exploits, this campaign succeeded through ruthless efficiency targeting fundamental security gaps. The threat actor did not exploit specific FortiGate software vulnerabilities. Instead, they conducted mass automated scanning for management interfaces exposed on ports 443, 8443, 10443, and 4443.

Once a target was identified, the actor attempted to authenticate using default or commonly reused credentials on devices lacking multi-factor authentication (MFA). If a target proved difficult—such as having patched services or closed ports—the attacker simply moved on, prioritizing "easy pickings" over persistence.

Key Technical Observations:

  • Scanning Origin: The mass scanning activity originated from the IP address 212.11.64[.]250.
  • Credential Theft: Successful breaches allowed the extraction of full device configurations, including SSL-VPN credentials and network topology maps.
  • Lateral Movement: Stolen data was used to pivot into internal networks, targeting Active Directory environments and backup infrastructure.
  • Targeted Vulnerabilities: While initial access relied on weak credentials, post-exploitation tools were designed to exploit known vulnerabilities in Veeam Backup & Replication, specifically CVE-2023-27532 and CVE-2024-40711.

Global Impact and Pre-Ransomware Indicators

The scope of the attack was indiscriminate and sector-agnostic, affecting organizations in South Asia, Latin America, the Caribbean, West Africa, Northern Europe, and Southeast Asia. The widespread nature of the campaign indicates an automated "spray and pray" approach supercharged by AI processing.

Amazon classifies this activity as a pre-ransomware staging operation. The attackers focused on extracting administrative passwords, mapping the network, and compromising backup systems—classic precursors to a devastating ransomware deployment. By compromising Veeam backup servers, the actors likely intended to disable recovery options, thereby increasing the leverage for future extortion demands.

Comparative Analysis: Traditional vs. AI-Augmented Operations

The following table illustrates how the integration of Generative AI transformed the capabilities of this specific threat actor compared to a traditional low-skilled adversary.

Comparison of Adversary Capabilities

Operational Aspect Traditional Low-Skilled Actor AI-Augmented Threat Actor (Observed)
Tool Development Relies on pre-existing scripts; unable to modify code. Generates custom Go/Python tools via AI prompts.
Attack Scale Manual or slow automated scanning. "Assembly line" automation across 55 countries.
Adaptability Stalls when standard tools fail. Uses AI to troubleshoot and generate fallback commands.
Target Selection Often opportunistic but inefficient. Rapidly filters for "soft" targets; abandons hardened ones.
Post-Exploitation Struggles with lateral movement. AI assists in navigating Active Directory and backups.

Implications for Cybersecurity Strategy

This campaign serves as a wake-up call for organizations relying on "security through obscurity." The ability of low-skilled actors to scale attacks using AI means that basic misconfigurations are now liabilities that will be discovered and exploited at machine speed.

CJ Moses emphasized that strong defensive fundamentals remain the most effective countermeasure. "As we expect this trend to continue in 2026, organizations should anticipate that AI-augmented threat activity will continue to grow," Moses stated.

Recommended Mitigations:

  1. Eliminate Exposure: Ensure FortiGate management interfaces are not exposed to the public internet.
  2. Enforce MFA: Implement multi-factor authentication for all VPN and administrative access points immediately.
  3. Patch Management: regularly update all perimeter devices and software, specifically patching known vulnerabilities like those in Veeam.
  4. Network Segmentation: Isolate backup servers from general network access to prevent ransomware actors from crippling recovery efforts.

As Generative AI continues to mature, the distinction between "skilled" and "unskilled" hackers is blurring. This incident confirms that AI is not just a tool for defenders but a potent lever for adversaries, capable of turning a novice into a global threat.

Featured
ThumbnailCreator.com
AI-powered tool for creating stunning, professional YouTube thumbnails quickly and easily.
Video Watermark Remover
AI Video Watermark Remover – Clean Sora 2 & Any Video Watermarks!
AdsCreator.com
Generate polished, on‑brand ad creatives from any website URL instantly for Meta, Google, and Stories.
Refly.ai
Refly.AI empowers non-technical creators to automate workflows using natural language and a visual canvas.
VoxDeck
Next-gen AI presentation maker,Turn your ideas & docs into attention-grabbing slides with AI.
BGRemover
Easily remove image backgrounds online with SharkFoto BGRemover.
Flowith
Flowith is a canvas-based agentic workspace which offers free 🍌Nano Banana Pro and other effective models...
Qoder
Qoder is an agentic coding platform for real software, Free to use the best model in preview.
Skywork.ai
Skywork AI is an innovative tool to enhance productivity using AI.
FineVoice
Clone, Design, and Create Expressive AI Voices in Seconds, with Perfect Sound Effects and Music.
FixArt AI
FixArt AI offers free, unrestricted AI tools for image and video generation without sign-up.
Elser AI
All-in-one AI video creation studio that turns any text and images into full videos up to 30 minutes.
Pippit
Elevate your content creation with Pippit's powerful AI tools!
SharkFoto
SharkFoto is an all-in-one AI-powered platform for creating and editing videos, images, and music efficiently.
Funy AI
AI bikini & kiss videos from images or text. Try the AI Clothes Changer & Image Generator!
KiloClaw
Hosted OpenClaw agent: one-click deploy, 500+ models, secure infrastructure, and automated agent management for teams and developers.
Diagrimo
Diagrimo transforms text into customizable AI-generated diagrams and visuals instantly.
SuperMaker AI Video Generator
Create stunning videos, music, and images effortlessly with SuperMaker.
AI Clothes Changer by SharkFoto
AI Clothes Changer by SharkFoto instantly lets you virtually try on outfits with realistic fit, texture, and lighting.
Yollo AI
Chat & create with your AI companion. Image to Video, AI Image Generator.
AnimeShorts
Create stunning anime shorts effortlessly with cutting-edge AI technology.
HappyHorseAIStudio
Browser-based AI video generator for text, images, references, and video editing.
InstantChapters
Create Youtube Chapters with one click and increase watch time and video SEO thanks to keyword optimized timestamps.
NerdyTips
AI-powered football predictions platform delivering data-driven match tips across global leagues.
WhatsApp AI Sales
WABot is a WhatsApp AI sales copilot that delivers real-time scripts, translations, and intent detection.
happy horse AI
Open-source AI video generator that creates synchronized video and audio from text or images.
insmelo AI Music Generator
AI-driven music generator that turns prompts, lyrics, or uploads into polished, royalty-free songs in about a minute.
AI Video API: Seedance 2.0 Here
Unified AI video API offering top-generation models through one key at lower cost.
wan 2.7-image
A controllable AI image generator for precise faces, palettes, text, and visual continuity.
BeatMV
Web-based AI platform that turns songs into cinematic music videos and creates music with AI.
Kirkify
Kirkify AI instantly creates viral face swap memes with signature neon-glitch aesthetics for meme creators.
Text to Music
Turn text or lyrics into full, studio-quality songs with AI-generated vocals, instruments, and multi-track exports.
UNI-1 AI
UNI-1 is a unified image generation model combining visual reasoning with high-fidelity image synthesis.
Iara Chat
Iara Chat: An AI-powered productivity and communication assistant.
Wan 2.7
Professional-grade AI video model with precise motion control and multi-view consistency.
Tome AI PPT
AI-powered presentation maker that generates, beautifies, and exports professional slide decks in minutes.
Lyria3 AI
AI music generator that creates high-fidelity, fully produced songs from text prompts, lyrics, and styles instantly.
kinovi - Seedance 2.0 - Real Man AI Video
Free AI video generator with realistic human output, no watermark, and full commercial use rights.
Video Sora 2
Sora 2 AI turns text or images into short, physics-accurate social and eCommerce videos in minutes.
Atoms
AI-driven platform that builds full‑stack apps and websites in minutes using multi‑agent automation, no coding required.
AI Pet Video Generator
Create viral, shareable pet videos from photos using AI-driven templates and instant HD exports for social platforms.
Ampere.SH
Free managed OpenClaw hosting. Deploy AI agents in 60 seconds with $500 Claude credits.
Paper Banana
AI-powered tool to convert academic text into publication-ready methodological diagrams and precise statistical plots instantly.
Hitem3D
Hitem3D converts a single image into high-resolution, production-ready 3D models using AI.
HookTide
AI-powered LinkedIn growth platform that learns your voice to create content, engage, and analyze performance.
GenPPT.AI
AI-driven PPT maker that creates, beautifies, and exports professional PowerPoint presentations with speaker notes and charts in minutes.
Create WhatsApp Link
Free WhatsApp link and QR generator with analytics, branded links, routing, and multi-agent chat features.
Palix AI
All-in-one AI platform for creators to generate images, videos, and music with unified credits.
Gobii
Gobii lets teams create 24/7 autonomous digital workers to automate web research and routine tasks.
Seedance 20 Video
Seedance 2 is a multimodal AI video generator delivering consistent characters, multi-shot storytelling, and native audio at 2K.
Veemo - AI Video Generator
Veemo AI is an all-in-one platform that quickly generates high-quality videos and images from text or images.
AI FIRST
Conversational AI assistant automating research, browser tasks, web scraping, and file management through natural language.
WhatsApp Warmup Tool
AI-powered WhatsApp warmup tool automates bulk messaging while preventing account bans.
AirMusic
AirMusic.ai generates high-quality AI music tracks from text prompts with style, mood customization, and stems export.
GLM Image
GLM Image combines hybrid AR and diffusion models to generate high-fidelity AI images with exceptional text rendering.
Manga Translator AI
AI Manga Translator instantly translates manga images into multiple languages online.
TextToHuman
Free AI humanizer that instantly rewrites AI text into natural, human-like writing. No signup required.
ainanobanana2
Nano Banana 2 generates pro-quality 4K images in 4–6 seconds with precise text rendering and subject consistency.
Free AI Video Maker & Generator
Free AI Video Maker & Generator – Unlimited, No Sign-Up
Remy - Newsletter Summarizer
Remy automates newsletter management by summarizing emails into digestible insights.
Telegram Group Bot
TGDesk is an all-in-one Telegram Group Bot to capture leads, boost engagement, and grow communities.

AI-Assisted Hacker Breaches 600+ FortiGate Firewalls Across 55 Countries, Amazon Reports

Amazon Threat Intelligence revealed that a Russian-speaking actor used commercial generative AI tools to breach over 600 FortiGate devices in 55 countries in a pre-ransomware campaign.