Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Infostealers Drive Massive Brute-Force Attacks on Corporate SSO Gateways with Stolen Credentials

Recent cybersecurity analysis reveals an increase in credential-stuffing attacks targeting corporate Single Sign-On (SSO) systems, with F5 BIG-IP devices being a significant focus. Defused Cyber analyzed 70 unique email-password pairs used in these…

Recent cybersecurity analysis reveals an increase in credential-stuffing attacks targeting corporate Single Sign-On (SSO) systems, with F5 BIG-IP devices being a significant focus. Defused Cyber analyzed 70 unique email-password pairs used in these attacks, finding that 77% matched with data from Infostealer infections, showing a connection between data harvested by Infostealers and brute-force attempts on corporate SSO infrastructure.

The stolen credentials were not directly obtained from F5 systems but from compromised employee devices infected with malware like RedLine, Raccoon, or Vidar, which collect browser-saved credentials. These credentials were then used for credential stuffing attacks against corporate portals, relying on password reuse or weak multi-factor authentication (MFA) enforcement.

This campaign illustrates a systematic process where identity theft serves as the primary entry point:

Infection: An employee’s device is infected by an Infostealer, exfiltrating browser-stored credentials. Marketplace: Stolen logs are sold on underground markets to Initial Access Brokers (IABs). Front-Door Bypass: Attackers use these credentials against corporate edge systems like F5 BIG-IP. Network Compromise: Valid credentials allow direct system access.

The attack model emphasizes the importance of identity management over traditional network defenses, exploiting password reuse across systems. Analysis identified compromised credentials from several organizations, indicating widespread targeting across various sectors.

Organization Sector Compromised Domain

Rolls-Royce Aerospace & Defense @ps.rolls-royce.com

Marketplace: Stolen logs are sold on underground markets to Initial Access Brokers (IABs).
Joseph Cain · Thehackingpost

Johnson & Johnson Pharmaceuticals @its.jnj.com

Ericsson Telecommunications @ericsson.com

Deloitte Professional Services @deloitte.com

Belgian Police Law Enforcement @police.belgium.eu

Queensland Police Law Enforcement @police.qld.gov.au

Majid Al Futtaim Retail / Conglomerate @maf.ae

Advertisement

Cellebrite Digital Intelligence @cellebrite.com

Doka Engineering @doka.com

Turkish Ministry of Trade Government @ticaret.gov.tr

Attackers employ volume and statistical success, targeting high-value domains expecting some credentials to bypass MFA or cause user fatigue. Security strategies now require continuous identity monitoring and strict MFA enforcement.

Hijacked Infrastructure as Attack Proxies

Further investigation identified the source IP as a compromised Fortinet FortiGate-60E firewall in Japan. The device exposed open ports and used a self-signed SSL certificate, suggesting attackers are using hijacked devices as proxies for their operations. This shows an evolution in cybercriminal tactics, moving from exploiting vulnerabilities to abusing authentication processes.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories