Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants.

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. Gathering these credentials can then allow them to pivot to password spraying against services exposed to the internet, gaining credentials for other products and services. As this sort of attack occurs frequently, this article will be a resource repository of the following information about these attacks: Unit 42 recommends auditing remote access logs for suspicious activity with a focus on successful logins shortly after large volume password failure events.
If you think you might have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: Unit 42's Deep and Dark Web (DDW) monitoring is a service that assists clients in identifying sensitive information and leaked credentials that surface on the dark web, providing critical insights to reduce risk exposure and reduce the time between detection and response. Cortex Cloud Identity Security encompasses Cloud Infrastructure Entitlement Management (CIEM), Identity Security Posture Management (ISPM), Data Access Governance (DAG) as well as Identity Threat Detection and Response (ITDR) and provides clients with the necessary capabilities to improve their identity related security requirements. Additionally, Cortex Cloud provides protections against credentials that were compromised, lost or exposed being leveraged against cloud resources, such as those discussed within this article. Idira Identity Threat Protection enables security teams to counter identity-based attacks targeting Idira Next Generation Identity (NGI) Platform and the identities it secures.
Darkweb post of IAB selling credentials. Discovered credentials are automatically onboarded into a hardened digital vault for centralized management. Privilege Cloud then enforces programmatic transactional credential rotation using complex, randomized strings.
We continue to monitor our threat landscape for this and other identity-based attacks. Palo Alto Networks has shared our findings with our fellow Cyber Threat Alliance (CTA) members, including Fortinet. Learn more about the Cyber Threat Alliance . We will update this threat brief as more relevant information becomes available.
What changed
A large-scale password spraying and credential theft campaign (“FortiBleed”) against Fortinet devices was initially disclosed in June 2026 .
The attackers have leveraged a multi-stage process to gain persistent, high-privilege access: We observed an initial access broker (IAB) on the Russian-language cybercrime forum Exploit[.]in claiming responsibility for this campaign, referencing a CVE (no further information), and offering the harvested credentials for sale on June 16, 2026.
Palo Alto Networks customers receive assistance protecting against and mitigating credential attacks in the following ways: Palo Alto Networks also recommends the following hardening guidelines: The Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.
This eliminates the static, predictable passwords exploited during spraying attacks, removing standing privileges and blocking lateral movement across the network infrastructure and devices.
Updated August 18, 2026 at 1:30 p.m.
Who is affected
TheHatman claims to have sensitive or confidential information from several high-profile organizations, and this actor has claimed that they used compromised credentials through MFA fatigue and password spraying attacks to gain unauthorized access to these organizations.
Once the attackers obtain credentials, they add them to their password list for future attempts against additional targets, as well as for logging into accounts they successfully compromised.
SOCRadar provided the initial reporting on the targeting of FortiGate devices.
We encourage customers to implement the hunting and hardening recommendations to identify, mitigate, and prevent credential attacks against their networks.
Palo Alto Networks customers can leverage a variety of product protections and consulting services to identify and defend against this threat.
Idira Multi-Factor Authentication helps protect organizations against password spraying, credential theft, and other identity-based attacks by verifying that the person signing in is the legitimate user, not just someone with a valid password.
Why this matters
If you think you might have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: Unit 42's Deep and Dark Web (DDW) monitoring is a service that assists clients in identifying sensitive information and leaked credentials that surface on the dark web, providing critical insights to reduce risk exposure and reduce the time between detection and response.
Cortex Cloud Identity Security encompasses Cloud Infrastructure Entitlement Management (CIEM), Identity Security Posture Management (ISPM), Data Access Governance (DAG) as well as Identity Threat Detection and Response (ITDR) and provides clients with the necessary capabilities to improve their identity related security requirements.
Additionally, Cortex Cloud provides protections against credentials that were compromised, lost or exposed being leveraged against cloud resources, such as those discussed within this article.
Idira Identity Threat Protection enables security teams to counter identity-based attacks targeting Idira Next Generation Identity (NGI) Platform and the identities it secures.
Using near real-time detection, powered by CORA AI, and leveraging Idira’s visibility across multiple contexts (like PAM, authentication, SSO, cloud, endpoints, browsers, and more), Idira ITP can apply automated, tailored non-disruptive in-session response to contain and minimize potential identity-based threats.
Idira Privileged Access Management is a SaaS-delivered Privileged Access Management (PAM) solution that mitigates credential compromise and password spraying by prioritizing automated discovery, onboarding, and rotation.
The technical picture
Darkweb post of IAB selling credentials.
Discovered credentials are automatically onboarded into a hardened digital vault for centralized management.
Privilege Cloud then enforces programmatic transactional credential rotation using complex, randomized strings.
How organizations are responding
We continue to monitor our threat landscape for this and other identity-based attacks.
Palo Alto Networks has shared our findings with our fellow Cyber Threat Alliance (CTA) members, including Fortinet.
Learn more about the Cyber Threat Alliance .
We will update this threat brief as more relevant information becomes available.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.
Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.
What remains unknown
The available reporting does not establish who is behind the activity, if an attacker is involved.