IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

SonicWall Credential Attacks

July 25–27, 2026 Credential Stuffing, MySonicWall Configuration Exposure, and Akira Attribution Boundaries

Credential stuffingValid accountsFirewall / VPN
Published
Aug 12, 2026
Brief Version
v1.1
Updated
Aug 12, 2026
AI Monitor
Card Library review queue
Brief ID
PANDA-FTIB-SONICWALL-CREDENTIAL-2026-001
Template
Flash Threat Brief v2.0
  • What happened: From July 25–27, 2026, Huntress observed broad credential stuffing that produced successful SonicWall VPN/firewall logins across 30 organizations.1
  • How cloud backup can become on-premises access: A stolen .EXP backup can reveal the exact firewall, exposed VPN/management services, accounts, authentication backends, policies, routes, and trust relationships. If the attacker also obtains a working credential, session, shared secret, attacker-controlled TOTP enrollment, or another permitted path, the firewall can grant a legitimate-looking session whose assigned routes lead into the internal network. The backup is a targeting map, not automatic proof that encrypted secrets or MFA were defeated.2, 3, 4, 6
  • What is known: Five source IPs, 92 affected accounts, successful logins, and the July 25–27 window are public. Actor identity, credential origin, and follow-on compromise were not established.1
  • What to do: Hunt the five IPs and successful sessions, reset affected and backup-exposed trust material, invalidate sessions/TOTP, validate every authentication path, and scope internal access before declaring the appliance safe.1, 3

SonicWall firewalls and VPNs are the gatekeepers between the internet and internal business systems. On July 25–27, 2026, Huntress observed attackers testing stolen or reused credentials at scale and successfully logging into SonicWall services at 30 organizations. Because the activity used working accounts rather than a demonstrated software exploit, installing the latest firmware alone does not answer whether access occurred.1

The credential source is unknown, but the separate 2025 MySonicWall incident explains why a cloud backup can matter to an on-premises firewall. SonicWall says an .EXP backup is a full device snapshot. Its general configuration becomes readable after simple decoding and can expose the exact appliance, enabled internet-facing services, VPN policies, accounts, authentication servers, routes, network objects, and peer relationships. Passwords and keys remain individually encrypted, so possession is not the same as having every secret. Even so, the file removes much of an attacker's reconnaissance work and identifies precisely which credentials, portals, shared secrets, and trust paths are worth targeting. SonicWall's unusually broad reset matrix—local users, TOTP bindings, LDAP/RADIUS/TACACS secrets, IPSec keys, APIs, routing and management credentials—reflects that risk. No retained source proves these backups supplied the July 2026 credentials.2, 3

The next step requires usable access material or a weak path. An attacker can combine the configuration map with a separately stolen or reused password, unchanged VPN/shared secret, active session, or other configured trust. Rapid7 documented one concrete apparent-MFA-bypass mechanism in separate Akira cases: an attacker with a valid username and password could reach a publicly exposed Virtual Office portal and bind the attacker's own TOTP before using SSLVPN. SonicWall also warns that default LDAP-group configuration can authorize users more broadly than intended. Thus a fully patched appliance with 'MFA enabled' can still admit an attacker when the actual login path allows hostile enrollment, session reuse, over-broad authorization, or a service outside the expected MFA policy. Once the firewall grants the session, it can legitimately route that attacker toward the internal systems allowed for the identity or tunnel.4, 6, 3

Do not collapse the evidence into one Akira story. Akira has supported historical use of SonicWall SSLVPN and valid-account conditions, but the July credential-stuffing campaign is unattributed. SonicWall described the MySonicWall actor as state-sponsored, while the public evidence reviewed does not connect that incident to Akira. The INC/SMA1000 zero-day campaign affects a different SonicWall product and remains separate.1, 4, 7, 8

The decision is to treat successful authentication as a potential incident. Preserve logs, identify every affected account and session, complete the vendor credential-reset matrix, rebind TOTP, validate local and directory authorization, review configuration and internal access, and document whether the evidence supports attempts only, perimeter access, downstream compromise, data loss, or ransomware.1, 3

Date / Period
September–October 2025 · MySonicWall
Event / Meaning
SonicWall disclosed unauthorized access to cloud-stored firewall configuration backups and ultimately said all cloud-backup users were affected; credential-reset guidance followed.2, 3
Sources
2, 3
Date / Period
2025 · Akira / SSLVPN lane
Event / Meaning
SonicWall and Rapid7 reporting linked separate Akira activity to SSLVPN access, CVE-2024-40766/legacy credential conditions, and authentication configuration risks.4, 5
Sources
4, 5
Date / Period
July 25, 2026
Event / Meaning
Huntress observed 26 affected accounts across six organizations.1
Sources
1
Date / Period
July 26, 2026
Event / Meaning
Huntress observed 34 affected accounts across 16 organizations.1
Sources
1
Date / Period
July 27, 2026
Event / Meaning
Huntress observed 32 affected accounts across eight organizations, completing the published July 25–27 campaign window.1
Sources
1
Date / Period
2026 · Marquis allegation
Event / Meaning
Marquis alleged that configuration data stolen from SonicWall cloud backup enabled attackers to circumvent its firewall and cause a ransomware incident; the conclusion is retained as a case-specific allegation, not a public Akira attribution or proof for the July campaign.9
Sources
9

This public brief retains defensible detection and scoping observables, not raw attacker infrastructure or operational instructions. Validate against owned telemetry before blocking or attributing.

Observable
157.245.88[.]153
Defender Use
Huntress July 25–27, 2026 campaign source IP; validate time, direction, and session outcome before blocking or attributing.1
Sources
1
Observable
162.243.31[.]111
Defender Use
Huntress July 25–27, 2026 campaign source IP.1
Sources
1
Observable
167.71.150[.]1
Defender Use
Huntress July 25–27, 2026 campaign source IP.1
Sources
1
Observable
209.97.151[.]148
Defender Use
Huntress July 25–27, 2026 campaign source IP.1
Sources
1
Observable
64.227.15[.]20
Defender Use
Huntress July 25–27, 2026 campaign source IP.1
Sources
1
Observable
Hashes, malware filenames, and domains
Defender Use
None were published for this credential-stuffing campaign. Do not import Akira, MySonicWall, or SMA1000 indicators into this set.1
Sources
1