Security1 distinct publisher3 min readUpdated
TheHatman's claimed Entra haul and the FortiBleed spraying wave share one detectable seam: a successful authentication landing just behind a spike of failures.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Unit 42 has refreshed its running brief on large-scale credential attacks, adding two 2026 cases: an actor called TheHatman claiming mass credential theft from Microsoft Entra tenants, and the FortiBleed password-spraying campaign against Fortinet devices [1][3][8]. The operational takeaway is narrower and more useful than the case studies: audit remote access logs for successful logins shortly after high-volume password failure events [16].
Start with what is actually established. Between Aug. 1 and Aug. 17, 2026, an actor using the handle TheHatman posted across multiple forums offering to sell employee information from multiple enterprises, allegedly exfiltrated from organizations' Microsoft Entra tenants [4]. That is a 17-day selling window [18]. TheHatman claims the access came from compromised credentials obtained through MFA fatigue and password spraying [6]. Unit 42 says it has not verified those claims and has been unable to verify a specific intrusion vector [5][6]. The activity was publicly reported as early as Aug. 16, 2026, with Unit 42 offering initial guidance on social media [7].
FortiBleed is better documented as tradecraft. Disclosed in June 2026 as a large-scale password spraying and credential theft campaign against Fortinet devices [8], it also reached MSSQL services, with reports of Sophos devices targeted as well [9]. Unit 42 says the activity is not aimed at Palo Alto Networks devices but that it has blocked suspicious login attempts in customer telemetry [10]. The attackers work from a curated password list that Unit 42 assesses was likely built from prior breaches, including successful exploitation of vulnerabilities [11]. Stage one is internet-wide scanning and spraying against Fortinet, Sophos and MSSQL; stage two is pulling device configuration files with stored credentials, potentially after exploiting a privilege escalation flaw; stage three is offline cracking [13]. Everything cracked goes back into the list, both to hit new targets and to log into already-compromised devices as an administrator [12][13]. That loop is the whole point: each victim subsidises the next round.
Attribution stays thin. An initial access broker on the Russian-language forum Exploit[.]in claimed responsibility, referenced a CVE without further detail, and offered the harvested credentials for sale on June 16, 2026 [14]. Unit 42 has not validated that either [14]. SOCRadar provided the initial reporting on FortiGate targeting [15]. Counting carefully, at least three of the central assertions in this brief are explicitly flagged as unverified by Unit 42 [19].
Which is why the detection guidance carries more weight than the naming. A spray campaign generates failure volume by construction, and the interesting event is not the noise but the one authentication that works immediately after it [16]. Unit 42 pairs that with edge device hardening [16]. Note the asymmetry, though: failure-spike correlation catches the FortiBleed pattern cleanly, while the MFA fatigue half of TheHatman's claimed method would leave its trail in push approvals and denials rather than password failures [6][13]. Two campaigns two months apart, two different log sources [20].
What to watch: whether anyone independently confirms TheHatman's Entra claims or the intrusion vector, since as of this update Unit 42 has not [5]. Watch also for FortiBleed's cracked credentials surfacing against products outside the Fortinet, Sophos and MSSQL set already named [9][12]. And check retention before the hunt: correlating a success against a failure burst requires that both are still in the logs.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
TheHatman claimed the data was stolen using compromised credentials, but Unit 42 says it has been unable to verify a specific intrusion vector.
TheHatman claims to hold sensitive or confidential information from several high-profile organizations and says the access came from compromised credentials obtained through MFA fatigue and password spraying attacks; Unit 42 has not verified these claims.
Unit 42 maintains a threat brief titled 'Mitigating Large-Scale Credential Attacks', updated August 18, structured as a resource repository of noteworthy large-scale credential attacks and mitigation guidance.
Unit 42 frames identity as the new perimeter, with attackers choosing to log in rather than break in, gathering previously leaked username and password pairs and pivoting to password spraying against internet-exposed services.
In August 2026, the actor TheHatman claimed to have stolen a large volume of credentials from organizations' Microsoft Entra tenants.
From Aug. 1 to Aug. 17, 2026, an actor using the handle 'TheHatman' made posts across multiple forums offering to sell employee information for multiple enterprises, allegedly exfiltrated from organizations' Microsoft Entra tenants.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party telemetry, single voice, key links unverified
The brief carries real observational weight — dated forum activity, an observed broker post, blocked login attempts in the vendor's own telemetry, and a specific three-stage attack chain — but it is one publisher speaking about its own visibility, it names no CVE, no victims, no volumes and no IOCs, and it explicitly declines to verify the actor and broker claims on which the narrative leans.
Two live campaigns with dated activity and vendor telemetry hits
Real-world incidence is concretely observed rather than hypothetical: a 17-day forum sale window in August 2026, a June 2026 spray campaign spanning Fortinet, Sophos and MSSQL surfaces, a dated broker sale offer, and suspicious login attempts blocked in customer telemetry. The ceiling is that no counts of affected organizations, credentials, or devices are given, so breadth cannot be sized.
Slightly overstated by branding and product attach, not by tone
The analytical body is unusually restrained — hedges are explicit, assessments are labelled as assessments, and the recommended action is a narrow, testable log-hunt heuristic. What pushes the gap mildly positive is packaging rather than substance: a named 'FortiBleed' campaign and an unverified actor's own boast about high-profile victims carry more weight than the evidence supplied, and the executive summary front-loads a list of the publisher's own products as protection.
Vendor-authored brief that routes to its own identity products
The sole source is a security vendor's research arm publishing on the vendor's own domain, naming Cortex Cloud Identity Security, the Unit 42 Deep and Dark Web Service, and the Idira ITP/MFA/PAM line as protection, plus an incident-response engagement offer; it also volunteers that its own devices are not the target. That is a strong commercial alignment, tempered by explicit, self-limiting verification caveats that cut against pure marketing.
Fresh and specific, but single-source and self-limited
Confidence is limited by structure rather than quality: one publisher, no reproduced independent corroboration, unnamed CVE, and three core assertions the publisher itself will not stand behind. It is lifted by recency (published Aug. 18, 2026, days after the activity), dated specifics, and first-party telemetry, so the operational guidance can be trusted further than the attribution narrative.
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
product
The number in the Palo Alto-NTT DATA deal is not $1 billion. It is 80 machine accounts per human2 distinct publishers
build
Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout1 distinct publisher
security
Kimwolf's new flood wears Chrome's fingerprints and takes orders from a blockchain1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026