As modern security perimeters shift toward identity-based access, cybercriminals increasingly rely on logging in rather than breaking in. According to Unit 42, attackers frequently aggregate previously leaked username and password pairs to fuel automated credential attacks against internet-facing infrastructure.
Understanding the Threat Landscape
Recent intelligence highlights a surge in large-scale password spraying and credential stuffing operations targeting various corporate environments. Threat actors utilize curated password lists derived from historical data breaches and newly exploited vulnerabilities to target edge infrastructure, including Fortinet and Sophos devices, alongside Microsoft Entra tenants.
During August 2026, a threat actor operating under the handle “TheHatman” posted offers on cybercrime forums to sell employee data allegedly exfiltrated from corporate Microsoft Entra tenants. While the actor claimed to leverage compromised credentials obtained through MFA fatigue and password spraying, security researchers have noted that exact initial access vectors remain difficult to verify independently. Concurrently, campaigns such as “FortiBleed” have demonstrated how initial access brokers weaponize stolen credentials to pivot across exposed services.
Attack Mechanics and TTPs
Attackers typically execute a multi-stage process to establish persistence and escalate privileges within targeted networks:
- Credential Gathering: Aggregating leaked credentials from previous breaches and underground forums.
- Password Spraying: Launching low-and-slow authentication attempts against exposed remote access services to avoid triggering account lockout thresholds.
- MFA Exploitation: Utilizing prompt fatigue techniques to bypass multi-factor authentication controls.
- Lateral Movement: Pivoting from compromised edge devices into internal cloud and on-premises environments.
Actionable Recommendations and Mitigations
Defenders must prioritize proactive threat hunting and perimeter hardening to disrupt identity-based campaigns. Organizations should implement the following security measures:
- Log Analysis: Audit remote access logs specifically for successful logins occurring shortly after high-volume password failure events.
- Edge Hardening: Review and enforce strict hardening guidelines for all internet-exposed edge devices and VPN gateways.
- Identity Monitoring: Deploy Identity Threat Detection and Response (ITDR) solutions to identify anomalous access patterns and compromised cloud identities in real-time.
- MFA Policy Tuning: Implement phishing-resistant multi-factor authentication, such as FIDO2-compliant security keys, to neutralize MFA fatigue tactics.
Related: Identity Attacks & MFA Bypass: The New Ransomware Entry Point, Zero-Click AI Browser Hacking Threatens Claude and ChatGPT Atlas