Connect with us

Hi, what are you looking for?

AI Cybersecurity

AWS Reports AI-Enhanced Attack Compromises Over 600 FortiGate Firewalls Worldwide

AWS reveals over 600 Fortinet FortiGate firewalls were compromised in a generative AI-enhanced cyberattack affecting 55+ countries from January to February 2026.

More than 600 Fortinet FortiGate firewalls were compromised in a cyberattack orchestrated by less sophisticated actors utilizing generative AI tools, according to a recent report from Amazon Web Services (AWS). The attack, which spanned from January 11 to February 18, 2026, affected devices across over 55 countries, including regions in Africa, Asia, Latin America, North America, and Europe.

Stephen Schmidt, Amazon’s Chief Security Officer, emphasized the role of AI in this incident, stating, “AI is making certain types of attacks more accessible to less sophisticated actors who can now leverage AI to enhance their capabilities and operate at greater scale.” The report indicated that the attackers, described as a Russian-speaking group or individual with limited technical skills, were not affiliated with any state-sponsored threat groups.

Schmidt noted that the use of AI allowed these actors to generate attack plans and tools while automating operations in ways that traditionally required considerable resources and expertise. “This is part of a pattern we’re seeing where AI is lowering the barrier to entry for threat actors,” he added.

The incident report detailed how the perpetrators employed various commercial generative AI services throughout their operation to implement and scale established attack techniques. The attackers reportedly used at least two large language models to coordinate the assault, assessing the duration and anticipated success rates of their efforts.

According to CJ Moses, AWS’s Chief Information Security Officer, the attackers’ plans even referenced academic literature on offensive AI agents, indicating they are keeping abreast of advancements in AI-assisted penetration testing. “The AI produces technically accurate command sequences, but the actor struggles to adapt when conditions differ from the plan,” Moses explained.

The report also highlighted that the attackers successfully compromised multiple organizations’ Active Directory environments and targeted backup infrastructures, which could potentially lead to ransomware deployment. The hackers developed AI-assisted Python scripts to analyze stolen configurations and employed open-source tools to exploit known vulnerabilities in systems, including Veeam Backup & Replication servers.

Moses pointed out that the attackers demonstrated an opportunistic approach; when faced with fortified defenses, they simply moved on to softer targets rather than attempting to breach more complex systems. “Notably, when this actor encountered hardened environments or more sophisticated defensive measures, they simply moved on to softer targets rather than persisting, underscoring that their advantage lies in AI-augmented efficiency and scale, not in deeper technical skill,” Moses stated.

AWS’s infrastructure was not implicated in the attack, and the report indicated that no FortiGate vulnerabilities were exploited during the campaign. The company advises customers using FortiGate appliances to take immediate security measures, such as ensuring management interfaces are not exposed to the internet and changing default credentials for accounts.

Additional recommended actions include auditing for password reuse between FortiGate VPN credentials and Active Directory domain accounts, implementing multi-factor authentication for all VPN access, and rotating service account credentials. Schmidt concluded, “AI is changing security on both sides of the equation, but organizations that combine strong security fundamentals with AI-powered tools are well-positioned to stay ahead.” This incident underscores the evolving nature of cyber threats and the increasing role of AI in facilitating attacks, raising concerns about the future landscape of cybersecurity.

See also
Rachel Torres
Written By

At AIPressa, my work focuses on exploring the paradox of AI in cybersecurity: it's both our best defense and our greatest threat. I've closely followed how AI systems detect vulnerabilities in milliseconds while attackers simultaneously use them to create increasingly sophisticated malware. My approach: explaining technical complexities in an accessible way without losing the urgency of the topic. When I'm not researching the latest AI-driven threats, I'm probably testing security tools or reading about the next attack vector keeping CISOs awake at night.

You May Also Like

AI Regulation

China enacts strict AI regulations ahead of July 15, banning harmful content for minors to ensure safe and responsible tech development.

AI Cybersecurity

AI-powered walk-through metal detectors achieve a 70% reduction in false alarms, enhancing security efficiency in high-traffic environments like airports and corporate buildings.

AI Regulation

Dykema’s 2026 Automotive Trends Report reveals 61% of industry leaders cite supply chain litigation as the top concern amid rising regulatory pressures.

AI Technology

Super Micro launches compact edge AI systems powered by AMD EPYC 4005 processors, enhancing real-time analytics for retail and healthcare amid a volatile stock...

AI Government

Leopold Aschenbrenner warns that AI could surpass college graduates by 2026, posing unprecedented national security risks reminiscent of the atomic bomb.

Top Stories

Lumentum secures a $2 billion investment from Nvidia, boosting its optical components order book through 2028 amid surging AI demand from hyperscalers.

AI Regulation

Legal experts caution against AI regulation overreach, warning that hasty laws may benefit large corporations while stifling innovation and competition.

Top Stories

Google.org commits $10M to train 40,000 manufacturing workers in AI skills, addressing a critical skills gap in the rapidly evolving industrial sector

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.