ZenoX, a Brazilian cybersecurity company, found that certain username and password pairs were repeated across thousands of distinct IP addresses in the FortiBleed campaign, suggesting they may be planted backdoor accounts rather than organic credentials.