TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Artificial Intelligence

AWS: AI Campaign Breaches 600+ FortiGate Firewalls in One Month

Paul Balo by Paul Balo
February 23, 2026
in Artificial Intelligence, Cloud, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • AWS has detailed a sweeping cyber campaign in which attackers used off-the-shelf generative AI tools to compromise more than 600 internet-exposed FortiGate firewalls across 55 countries...
  • The activity, which ran from mid-January to mid-February, shows how generative AI is helping relatively low-skilled, financially motivated groups automate attacks that once required larger, more...
  • According to AWS’s incident report, the Russian-speaking group behind the campaign did not rely on novel zero-day exploits.

AWS has detailed a sweeping cyber campaign in which attackers used off-the-shelf generative AI tools to compromise more than 600 internet-exposed FortiGate firewalls across 55 countries in just over a month.

The activity, which ran from mid-January to mid-February, shows how generative AI is helping relatively low-skilled, financially motivated groups automate attacks that once required larger, more experienced teams.

According to AWS’s incident report, the Russian-speaking group behind the campaign did not rely on novel zero-day exploits. Instead, they took a volume-based approach: scanning the internet for FortiGate management interfaces, testing weak or commonly reused credentials, and then moving quickly once they gained access.

Once a firewall was breached, the attackers pulled configuration files that held sensitive details, including:

  • Administrator and VPN credentials
  • Network topology information
  • Firewall rules

Those configuration files effectively served as a roadmap to victim environments. Using that insight, the group pushed deeper into networks, targeting systems such as Active Directory, harvesting more credentials, and looking for lateral movement paths. Backup platforms, including Veeam servers, were also among the systems they sought to access.

AWS says the group leaned on multiple commercial generative AI tools throughout this process. The tools were reportedly used to generate attack playbooks, scripts, and operational notes, indicating that AI was integrated across the workflow rather than used just for occasional code snippets.

Investigators found evidence of AI-generated code and planning artifacts on compromised infrastructure. The nature of the tooling suggested that the campaign’s sophistication was less about elite human development skills and more about what could be quickly assembled with AI assistance.

“The volume and variety of custom tooling would typically indicate a well-resourced development team,” said CJ Moses, CISO at Amazon. “Instead, a single actor or very small group generated this entire toolkit through AI-assisted development.”

Also worth reading
Proofpoint Says Paying Ransomware Gangs Can Invite A Second Demand AWS Security Hub Now Watches Azure As AI Workloads Become A Bigger Target Context Bombing Turns Prompt Injection Into A Defence Against AI Hackers JadePuffer: The First Fully AI-Powered Ransomware Attack Has Arrived Pentagon Taps Nvidia, Microsoft And AWS To Bring AI To Classified Networks Amazon Q1 2026 Earnings: AWS and AI Drive Strong Growth Despite Spending Concerns

AWS notes that the custom tools observed in the incident were functional but far from polished. Parsing logic was described as simplistic, and the code contained redundant comments that pointed to a machine-generated first draft. Despite that, the automation was effective enough to drive a broad campaign across dozens of countries.

The attackers appeared to favour speed and breadth over persistence. When they encountered defences that made progress difficult, they often abandoned those targets and moved on to easier ones. This behaviour underscores the opportunistic nature of the campaign: the goal was to compromise as many exposed systems as possible with minimal effort per target.

The geographic spread was wide and not sharply focused on any particular country or sector. Victims were scattered across parts of Europe, Asia, Africa, and Latin America. AWS observed clusters of activity that may point to compromises of managed service providers or shared environments, raising the possibility of amplified downstream impact when a single breach opened doors to multiple customer networks.

While the attack’s AI angle is notable, the defensive guidance from AWS centres on long-standing fundamentals. The report stresses that relatively basic security hygiene could have blocked much of the campaign:

  • Keeping management interfaces, such as firewall admin consoles, off the public internet
  • Enforcing multi-factor authentication (MFA) for administrative access
  • Avoiding password reuse and weak credentials

Because the attackers relied heavily on exposed interfaces and known-weak authentication practices, organizations that had already locked down access paths and enforced stronger identity controls would likely have been far less attractive targets.

The incident also fits into a broader pattern highlighted by other major providers. AWS’s findings come only weeks after Google warned that criminals are increasingly wiring generative AI directly into their operations, including using tools like its Gemini chatbot for reconnaissance, target profiling, phishing, and elements of malware development.

Taken together, these reports suggest that generative AI is becoming part of the standard toolkit for cybercrime groups, lowering the barrier to entry for complex, multi-step operations and allowing small teams or even single operators to run wide-reaching campaigns.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • github
    GitHub Confirms Hackers Stole Data From About 3,800…
  • shutterstock_1960378399-min-scaled
    China’s New Telecom Backdoor Shows Cybersecurity Is…
  • Palo-Alto-Networks-zero-day
    Critical Palo Alto PAN-OS Zero-Day Exploited in the…
  • 2024.02.06-US-Treasury-Department-sanctions-six-Iranian-hackers-responsible-for-malicious-cyber-activities-on-critical-infrastructure
    Iran-Linked Hackers Are Actively Disrupting US…
  • GettyImages-1561639950
    JadePuffer: The First Fully AI-Powered Ransomware…
  • 4155155-0-11998000-1775642746-shutterstock_2533498743
    Google Links First-Ever Zero-Day Discovery to…
  • OpenClaw moltbot AI assistant
    OpenClaw’s Viral Rise Exposes Security Risks in Agentic AI
  • AI_Risks-ChatGPT
    OpenAI Confirms Hack Linked to TanStack Attack
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Artificial Intelligence Cloud Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: ai securityawsfortigate
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • SpaceX Deploys V3 Starlink Satellites But Loses Another Super Heavy Booster July 26, 2026
  • The Boring Company Reportedly Seeks $4B As Musk’s Tunnel Bet Gets A $20B Valuation July 26, 2026
  • Claude Opus 5 Gives Anthropic A Cheaper Answer To The Fable 5 Problem July 25, 2026
  • Meta Makes Facebook Verified Free As AI Scams Make Real People Harder To Spot July 24, 2026
  • SAP Cloud Growth Eases Fears That AI Will Weaken Enterprise Software July 24, 2026
  • US Lawmakers Push AI Kill Switch Bill After OpenAI Rogue-Model Incident July 24, 2026
  • Airtel Money’s $61B Quarter Makes Its London IPO A Bigger Africa Fintech Story July 24, 2026
  • Intel Q2 Revenue Jumps As AI Compute Demand Lifts Chip Business July 24, 2026
  • AMD And Anthropic Deal Puts Real Pressure On Nvidia’s AI Chip Lead July 24, 2026
  • New York’s Data Centre Pause Shows AI Infrastructure Is Hitting Politics July 23, 2026
  • OpenAI Researcher’s $2B Drug Discovery Plan Shows AI Biotech Hype Is Back July 23, 2026
  • Airtel Africa Q1 Shows Mobile Money And Data Are Doing The Heavy Lifting July 23, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.