Skip to content

Security1 publisher3 min readPublished

Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures

TheHatman's claimed Entra haul and the FortiBleed spraying wave share one detectable seam: a successful authentication landing just behind a spike of failures.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures
Generated illustration

What happened

  • Unit 42 maintains a threat brief titled 'Mitigating Large-Scale Credential Attacks', updated August 18, structured as a resource repository of noteworthy large-scale credential attacks and mitigation guidance.
  • Unit 42 frames identity as the new perimeter, with attackers choosing to log in rather than break in, gathering previously leaked username and password pairs and pivoting to password spraying against internet-exposed services.
  • In August 2026, the actor TheHatman claimed to have stolen a large volume of credentials from organizations' Microsoft Entra tenants.
  • From Aug. 1 to Aug. 17, 2026, an actor using the handle 'TheHatman' made posts across multiple forums offering to sell employee information for multiple enterprises, allegedly exfiltrated from organizations' Microsoft Entra tenants.
  • TheHatman claimed the data was stolen using compromised credentials, but Unit 42 says it has been unable to verify a specific intrusion vector.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Unit 42 has refreshed its running brief on large-scale credential attacks, adding two 2026 cases: an actor called TheHatman claiming mass credential theft from Microsoft Entra tenants, and the FortiBleed password-spraying campaign against Fortinet devices [1][3][8]. The operational takeaway is narrower and more useful than the case studies: audit remote access logs for successful logins shortly after high-volume password failure events [16].

Start with what is actually established. Between Aug. 1 and Aug. 17, 2026, an actor using the handle TheHatman posted across multiple forums offering to sell employee information from multiple enterprises, allegedly exfiltrated from organizations' Microsoft Entra tenants [4]. That is a 17-day selling window [18]. TheHatman claims the access came from compromised credentials obtained through MFA fatigue and password spraying [6]. Unit 42 says it has not verified those claims and has been unable to verify a specific intrusion vector [5][6]. The activity was publicly reported as early as Aug. 16, 2026, with Unit 42 offering initial guidance on social media [7].

FortiBleed is better documented as tradecraft. Disclosed in June 2026 as a large-scale password spraying and credential theft campaign against Fortinet devices [8], it also reached MSSQL services, with reports of Sophos devices targeted as well [9]. Unit 42 says the activity is not aimed at Palo Alto Networks devices but that it has blocked suspicious login attempts in customer telemetry [10]. The attackers work from a curated password list that Unit 42 assesses was likely built from prior breaches, including successful exploitation of vulnerabilities [11]. Stage one is internet-wide scanning and spraying against Fortinet, Sophos and MSSQL; stage two is pulling device configuration files with stored credentials, potentially after exploiting a privilege escalation flaw; stage three is offline cracking [13]. Everything cracked goes back into the list, both to hit new targets and to log into already-compromised devices as an administrator [12][13]. That loop is the whole point: each victim subsidises the next round.

Attribution stays thin. An initial access broker on the Russian-language forum Exploit[.]in claimed responsibility, referenced a CVE without further detail, and offered the harvested credentials for sale on June 16, 2026 [14]. Unit 42 has not validated that either [14]. SOCRadar provided the initial reporting on FortiGate targeting [15]. Counting carefully, at least three of the central assertions in this brief are explicitly flagged as unverified by Unit 42 [19].

Which is why the detection guidance carries more weight than the naming. A spray campaign generates failure volume by construction, and the interesting event is not the noise but the one authentication that works immediately after it [16]. Unit 42 pairs that with edge device hardening [16]. Note the asymmetry, though: failure-spike correlation catches the FortiBleed pattern cleanly, while the MFA fatigue half of TheHatman's claimed method would leave its trail in push approvals and denials rather than password failures [6][13]. Two campaigns two months apart, two different log sources [20].

What to watch: whether anyone independently confirms TheHatman's Entra claims or the intrusion vector, since as of this update Unit 42 has not [5]. Watch also for FortiBleed's cracked credentials surfacing against products outside the Fortinet, Sophos and MSSQL set already named [9][12]. And check retention before the hunt: correlating a success against a failure burst requires that both are still in the logs.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories