Hackers Weaponize AI and Gemini in Cyberattacks, Breach France's FICOBA Database
Generative AI is lowering the barrier to cyberattacks. Hackers can use DeepSeek, Claude and the open-source CyberStrikeAI platform to automatically scan and compromise Fortinet firewalls at corporate branch offices. PromptSpy, an Android spyware strain, also integrates Google Gemini to evade detection, creating cascading risks for credentials, backups and financial data.
The related attacks date back to last December. Cybersecurity alerts issued on February 23 and March 4 said more than 600 misconfigured Fortinet firewalls across 55 countries had been compromised, with attackers stealing service-account credentials and network configurations. France's national bank-account database, FICOBA, was also accessed using stolen credentials, potentially exposing information on 1.2 million accounts.
All Coverage
8 original reportsThe Backstory
The history behind this eventHackers Use Stolen Gemini API Keys to Automate AI-Powered Cyberattacks
Trend Micro said generative AI is being used to combine content generation, credential theft and password-variant creation, allowing attackers to scale cybercrime with less technical expertise. The incident involved Google Gemini, Telegram and WordPress, underscoring how stolen API keys can become a key resource for automated attacks.
Trend Micro disclosed that a Russian-speaking threat actor had used 73 stolen Google Gemini API keys and jailbroken models since 2025, while concealing malicious activity through Telegram community channels. The operation successfully compromised 29 WordPress websites and also affected cryptocurrency wallets. No financial losses have been disclosed.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.