Credential Attacks Put Identity Controls Under Fresh Strain

Credential attack concept showing exposed remote access login under security monitoring.

Credential campaigns test the identity perimeter​

Unit 42 has updated its threat brief on large-scale credential attacks, warning that identity systems and exposed remote services remain a practical route into enterprise environments. The report links two recent areas of concern: unverified TheHatman claims involving Microsoft Entra tenants and the FortiBleed credential campaign against exposed services. The common defensive problem is not a single product flaw, but the reuse, testing and resale of credentials across internet-facing access points.

Identity is now a primary attack surface​

Unit 42 frames credential-based activity as a shift in attacker behavior: many intrusions now start with attempts to log in, not attempts to break in. The threat brief says attackers frequently collect previously leaked username and password pairs, then test them against services exposed to the public internet.

That approach makes identity controls part of the network perimeter. A valid username and password can reduce the need for noisy exploitation, especially when remote administration, database access or security appliances are reachable online. Password spraying also changes the signal defenders need to watch. Instead of one account receiving thousands of guesses, many accounts may receive a smaller number of attempts, making distributed failures harder to spot without correlation.

The implication is direct for security teams: credential hygiene, remote access visibility and edge-device hardening need to be managed together. Treating authentication logs as secondary evidence can leave the earliest stage of an attack hidden until an account has already been used successfully.


TheHatman claims remain unverified​

Unit 42 says an actor using the handle TheHatman posted across multiple forums from Aug. 1 to Aug. 17, 2026, offering to sell employee information for several enterprises. The actor allegedly claimed the data was exfiltrated from organizations' Microsoft Entra tenants.

The report is careful about attribution. Unit 42 says TheHatman claimed to have used compromised credentials, MFA fatigue and password spraying to gain unauthorized access, but the researchers have not verified a specific intrusion vector and have not verified the actor's claims. The activity was publicly reported as early as Aug. 16, 2026, and Unit 42 said it had offered initial guidance through social media.

That distinction matters. A forum sale post is not the same as confirmed compromise, and a claimed technique is not proof of how access occurred. For defenders, however, the claims still provide a useful prompt: review identity logs, tenant access patterns and recent successful logins that followed unusual authentication failure volume.


FortiBleed shows how exposed services amplify risk​

The same Unit 42 brief also covers the FortiBleed credential campaign, described as a large-scale password spraying and credential theft campaign initially disclosed in June 2026 against Fortinet devices. Unit 42 says it also observed attempts targeting MSSQL devices and saw reports of Sophos devices being targeted.

According to the report, the activity was not targeting Palo Alto Networks devices, though Unit 42 says suspicious login attempts were blocked in customer telemetry. The attackers used a curated password list to test exposed internet services. Unit 42 assesses that the initial list was likely built from a mix of previous breaches, including successful exploitation of vulnerabilities, and that newly obtained credentials were then added to the list for future attempts.

Unit 42 also observed an initial access broker on the Russian-language cybercrime forum Exploit claiming responsibility for the campaign, referencing a CVE without further information and offering harvested credentials for sale on June 16, 2026. The researchers say they have not validated that claim. The larger lesson is still clear: exposed management and service interfaces can turn old credential leaks into current access risk.


Log review is the first practical control​

Unit 42's most immediate recommendation is to audit remote access logs for suspicious activity, with particular focus on successful logins that occur shortly after large-volume password failure events. That pattern can indicate that spraying moved from unsuccessful guessing to valid credential use.

A useful review should connect failed authentication spikes, source patterns, target accounts and the first successful session after the failures. The goal is not simply to count bad passwords. It is to find the moment a credential may have worked, then determine what the account accessed, whether privileges changed and whether persistence was established.

This approach also helps separate background noise from actionable incidents. Internet-facing services always receive unwanted traffic, but a success following a failure wave deserves faster escalation than a generic failed-login alert.


Hardening priorities center on MFA and access exposure​

Unit 42 recommends strong phishing-resistant multi-factor authentication for remote services, along with policies that prevent management interfaces from being directly exposed to the public internet. The brief specifically points to jump boxes and Zero Trust Network Access policies as ways to narrow the attack surface for configuration theft and credential reuse.

The hardening list also includes changing default credentials, using long and complex passwords, rotating privileged credentials, implementing identity threat detection and response, disabling unused accounts, and keeping software and patches current. These measures are basic in description but demanding in execution, especially in hybrid environments with legacy accounts and scattered management planes.

For organizations deciding where to start, the report points toward exposed remote access as the highest-return audit zone. If a service accepts logins from the internet, it should have strong MFA, active monitoring, minimal privileged access and a documented reason for being reachable.


Conclusion​

Unit 42's update does not establish every public claim around TheHatman or FortiBleed as fact. It does, however, show why credential attacks remain a durable enterprise risk: old passwords, exposed services and uneven MFA coverage can combine into real access opportunities.

The defensive message is practical. Teams should review remote access logs, investigate successful logins after failure bursts, reduce public exposure of management interfaces and close gaps in MFA and privileged account handling. In credential-driven incidents, the earliest useful evidence is often already in the authentication trail.


Sources​


Editorial Team - CoinBotLab
  • Reading time 5 min read
  • Views28
  • Reading time 4 min read
  • Views18
  • Reading time 5 min read
  • Views27
  • Reading time 7 min read
  • Views35
  • Reading time 5 min read
  • Views33
  • Reading time 5 min read
  • Views25

Comments

There are no comments to display

Information

Author
CoinBotLab AI Editor
Published
Reading time
5 min read
Views
4

More by CoinBotLab AI Editor

Top