IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

SonicWall Credential Attacks

July 25–27, 2026 Credential Stuffing, MySonicWall Configuration Exposure, and Akira Attribution Boundaries

Credential stuffingValid accountsFirewall / VPN
Published
Aug 12, 2026
Brief Version
v1.1
Updated
Aug 12, 2026
AI Monitor
Card Library review queue
Brief ID
PANDA-FTIB-SONICWALL-CREDENTIAL-2026-001
Template
Flash Threat Brief v2.0
  • What happened: From July 25–27, 2026, Huntress observed broad credential stuffing that produced successful SonicWall VPN/firewall logins across 30 organizations.1
  • How cloud backup can become on-premises access: A stolen .EXP backup can reveal the exact firewall, exposed VPN/management services, accounts, authentication backends, policies, routes, and trust relationships. If the attacker also obtains a working credential, session, shared secret, attacker-controlled TOTP enrollment, or another permitted path, the firewall can grant a legitimate-looking session whose assigned routes lead into the internal network. The backup is a targeting map, not automatic proof that encrypted secrets or MFA were defeated.2, 3, 4, 6
  • What is known: Five source IPs, 92 affected accounts, successful logins, and the July 25–27 window are public. Actor identity, credential origin, and follow-on compromise were not established.1
  • What to do: Hunt the five IPs and successful sessions, reset affected and backup-exposed trust material, invalidate sessions/TOTP, validate every authentication path, and scope internal access before declaring the appliance safe.1, 3

SonicWall firewalls and VPNs are the gatekeepers between the internet and internal business systems. On July 25–27, 2026, Huntress observed attackers testing stolen or reused credentials at scale and successfully logging into SonicWall services at 30 organizations. Because the activity used working accounts rather than a demonstrated software exploit, installing the latest firmware alone does not answer whether access occurred.1

The credential source is unknown, but the separate 2025 MySonicWall incident explains why a cloud backup can matter to an on-premises firewall. SonicWall says an .EXP backup is a full device snapshot. Its general configuration becomes readable after simple decoding and can expose the exact appliance, enabled internet-facing services, VPN policies, accounts, authentication servers, routes, network objects, and peer relationships. Passwords and keys remain individually encrypted, so possession is not the same as having every secret. Even so, the file removes much of an attacker's reconnaissance work and identifies precisely which credentials, portals, shared secrets, and trust paths are worth targeting. SonicWall's unusually broad reset matrix—local users, TOTP bindings, LDAP/RADIUS/TACACS secrets, IPSec keys, APIs, routing and management credentials—reflects that risk. No retained source proves these backups supplied the July 2026 credentials.2, 3

The next step requires usable access material or a weak path. An attacker can combine the configuration map with a separately stolen or reused password, unchanged VPN/shared secret, active session, or other configured trust. Rapid7 documented one concrete apparent-MFA-bypass mechanism in separate Akira cases: an attacker with a valid username and password could reach a publicly exposed Virtual Office portal and bind the attacker's own TOTP before using SSLVPN. SonicWall also warns that default LDAP-group configuration can authorize users more broadly than intended. Thus a fully patched appliance with 'MFA enabled' can still admit an attacker when the actual login path allows hostile enrollment, session reuse, over-broad authorization, or a service outside the expected MFA policy. Once the firewall grants the session, it can legitimately route that attacker toward the internal systems allowed for the identity or tunnel.4, 6, 3

Do not collapse the evidence into one Akira story. Akira has supported historical use of SonicWall SSLVPN and valid-account conditions, but the July credential-stuffing campaign is unattributed. SonicWall described the MySonicWall actor as state-sponsored, while the public evidence reviewed does not connect that incident to Akira. The INC/SMA1000 zero-day campaign affects a different SonicWall product and remains separate.1, 4, 7, 8

The decision is to treat successful authentication as a potential incident. Preserve logs, identify every affected account and session, complete the vendor credential-reset matrix, rebind TOTP, validate local and directory authorization, review configuration and internal access, and document whether the evidence supports attempts only, perimeter access, downstream compromise, data loss, or ransomware.1, 3

Date / Period
September–October 2025 · MySonicWall
Event / Meaning
SonicWall disclosed unauthorized access to cloud-stored firewall configuration backups and ultimately said all cloud-backup users were affected; credential-reset guidance followed.2, 3
Sources
2, 3
Date / Period
2025 · Akira / SSLVPN lane
Event / Meaning
SonicWall and Rapid7 reporting linked separate Akira activity to SSLVPN access, CVE-2024-40766/legacy credential conditions, and authentication configuration risks.4, 5
Sources
4, 5
Date / Period
July 25, 2026
Event / Meaning
Huntress observed 26 affected accounts across six organizations.1
Sources
1
Date / Period
July 26, 2026
Event / Meaning
Huntress observed 34 affected accounts across 16 organizations.1
Sources
1
Date / Period
July 27, 2026
Event / Meaning
Huntress observed 32 affected accounts across eight organizations, completing the published July 25–27 campaign window.1
Sources
1
Date / Period
2026 · Marquis allegation
Event / Meaning
Marquis alleged that configuration data stolen from SonicWall cloud backup enabled attackers to circumvent its firewall and cause a ransomware incident; the conclusion is retained as a case-specific allegation, not a public Akira attribution or proof for the July campaign.9
Sources
9

This public brief retains defensible detection and scoping observables, not raw attacker infrastructure or operational instructions. Validate against owned telemetry before blocking or attributing.

Observable
157.245.88[.]153
Defender Use
Huntress July 25–27, 2026 campaign source IP; validate time, direction, and session outcome before blocking or attributing.1
Sources
1
Observable
162.243.31[.]111
Defender Use
Huntress July 25–27, 2026 campaign source IP.1
Sources
1
Observable
167.71.150[.]1
Defender Use
Huntress July 25–27, 2026 campaign source IP.1
Sources
1
Observable
209.97.151[.]148
Defender Use
Huntress July 25–27, 2026 campaign source IP.1
Sources
1
Observable
64.227.15[.]20
Defender Use
Huntress July 25–27, 2026 campaign source IP.1
Sources
1
Observable
Hashes, malware filenames, and domains
Defender Use
None were published for this credential-stuffing campaign. Do not import Akira, MySonicWall, or SMA1000 indicators into this set.1
Sources
1
#
1
Tier
Tier 2 - High-Value Research
Publisher
Huntress
Published
Checked Aug. 12, 2026
Why Used
Controlling source for July 25–27 activity, counts, successful logins, five IPs, credential-source uncertainty, and no observed follow-on at publication.
#
2
Tier
Tier 1 - Primary Authority
Publisher
SonicWall
Published
Updated Oct. 28, 2025
Why Used
Controls cloud-backup incident scope, .EXP sensitivity, encryption description, and remediation priority.
#
3
Tier
Tier 1 - Primary Authority
Publisher
SonicWall
Published
2025
Why Used
Controls the reset matrix for local users, TOTP, directory services, VPN secrets, and API/other keys.
#
4
Tier
Tier 2 - Primary Research
Publisher
Rapid7
Published
2025
Why Used
Controls its observed Akira, Virtual Office TOTP enrollment, LDAP authorization, lateral movement, data theft, backup, and encryption findings.
#
5
Tier
Tier 1 - Primary Authority
Publisher
SonicWall
Published
Aug. 2025
Why Used
Vendor boundary for separate SSLVPN/CVE-2024-40766 and migration-credential activity.
#
6
Tier
Tier 1 - Primary Authority
Publisher
SonicWall
Published
2025
Why Used
Controls the default LDAP authorization risk and intended group restriction guidance.
#
7
Tier
Tier 2 - Insurance Research
Publisher
Beazley Security
Published
2025
Why Used
Preserves the explicit no-established-link boundary between Akira and the MySonicWall backup incident.
#
8
Tier
Tier 3 - Corroborating News
Publisher
BleepingComputer
Published
2025
Why Used
Corroborates Mandiant/SonicWall state-actor and cloud-environment findings; does not identify the actor.
#
9
Tier
Tier 3 - Corroborating News
Publisher
BleepingComputer
Published
Jan. 29, 2026
Why Used
Retains the named victim's third-party-investigation conclusion and litigation context without promoting it into universal causation or Akira attribution.