News

Amazon Threat Intelligence Report: AI Cyberattack Hits 600 FortiGate Devices

Amazon Reports That AI-Powered Hackers Breached 600 Global FortiGate Firewalls

Written By : Anudeep Mahavadi
Reviewed By : Atchutanna Subodh

The latest Amazon Threat Intelligence report has shed some light on the importance of continued surveillance and security. The company’s investigation into the AI cyberattack campaign revealed that perpetrators gained control of over 600 devices across 55 countries. According to recent information, the campaign ran from January 11 to February 18. 

The attackers did not exploit advanced vulnerabilities. Instead, they targeted exposed management ports and weak, single-factor authentication settings.

 AI in Cybercrime as a Force Multiplier

The report shows how AI in cybercrime is reshaping threat operations. Commercially available AI tools were used to generate attack scripts, automate reconnaissance, and plan lateral movement inside networks. CJ Moses, Amazon CISO, stated that no FortiGate software vulnerabilities were exploited. Rather, “fundamental security gaps” allowed a low-to-medium-skilled actor to scale attacks rapidly. When stronger defenses were detected, the attackers shifted to easier targets, highlighting efficiency over sophistication.

Signs of Pre-Ransomware Operations

After breaching firewalls, the attackers extracted full device configurations. This includes SSL-VPN credentials, administrative passwords, and network maps. Stolen credentials enabled deeper intrusions into internal systems, including Active Directory environments and backup infrastructure

Amazon researchers found that the observed activity matched pre-ransomware staging activities. This indicates they are intended to prepare for forthcoming extortion campaigns instead of launching immediate system disruptions.

Also Read: Microsoft’s Massive Cyberattack: Hackers Infiltrate 100 Companies Worldwide

What This Means for Cybersecurity in 2026

The campaign did not rely on known CVEs but basic misconfigurations, which showed that cybersecurity hygiene gaps continue to exist. The research results show that AI enables threat actors to access their targets more quickly while increasing their operational capabilities. 

Amazon has shared indicators of compromise with partners and urged organizations to secure edge devices, enforce multi-factor authentication, and monitor post-exploitation activity. The defensive strategies of organizations need to develop at the same rate as AI adoption in their operations.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

$0.0004 Entry Won’t Stay Quiet: Apeing’s 300M-Token Stage and $0.01 Target Put It on the Radar of Trending Meme Coins Today

Maker vs Taker Fees: What They Mean, How Crypto Trading Fees Work in 2026

Visa Links On-Chain Credit to Stablecoin Card Working Capital

7 Cryptos Exploding Onto Investors’ Radars Today: Is Apeing the Next 100X Crypto Opportunity To Grab Before It Takes Off?

XRP Eyes CLARITY Act Vote as ETF Collateral Use Expands in US