Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

Imported from official source

Cybersecurity Classified by Officially

Identity has effectively become the new perimeter, where cybercriminals are increasingly choosing to log in rather than break in. To accomplish this, attackers frequently gather previously leaked username and password pairs. Gathering these credentials can then allow them to pivot to password spraying against services exposed to the internet, gaining credentials for other products and services.

As this sort of attack occurs frequently, this article will be a resource repository of the following information about these attacks:

  • Details of noteworthy large scale credential attacks 
  • Actionable guidance for mitigating these attacks
  • The Hatman attack: In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants
  • Fortibleed Credential Campaign: In June 2026, there was a large-scale password spraying campaign targeting Fortinet devices
  • Unit 42 recommends auditing remote access logs for suspicious activity with a focus on successful logins shortly after large volume password failure events. We also recommend reviewing and implementing the hardening guidance in this article for edge devices. 

    Palo Alto Networks customers are better protected from this activity through our products and services, such as:

    The Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.

    From Aug. 1–Aug. 17, 2026, an actor using the handle "TheHatman" made posts across multiple forums offering to sell employee information for multiple enterprises. TheHatman allegedly exfiltrated from organizations' Microsoft Entra tenants. While TheHatman has claimed this data was stolen using compromised credentials, we have been unable to verify a specific intrusion vector.

    This activity was publicly reported as early as Aug. 16, 2026, and we have offered initial guidance through social media.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://unit42.paloaltonetworks.com/large-scale-credential-attacks/

    Officially imported this from Palo Alto Networks Unit 42’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Palo Alto Networks Unit 42 — imported from official source
    Official source
    https://unit42.paloaltonetworks.com/feed/ RSS
    Imported
    September 18, 2026 11:34
    Versions
    1 recorded
    Identity
    https://unit42.paloaltonetworks.com/?p=182713

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.