SonicWall Credential Attacks
July 25–27, 2026 Credential Stuffing, MySonicWall Configuration Exposure, and Akira Attribution Boundaries
- Field
- User Topic
- Value
- Whether stolen SonicWall cloud backups or credentials can help an attacker enter a fully patched, MFA-enabled on-premises firewall, and how the July 25–27, 2026 credential-stuffing campaign should be treated.
- Field
- Interpreted Questions
- Value
- What is SonicWall, what happened July 25–27, what did the attackers achieve, where might credentials have come from, can configuration data explain apparent MFA bypass, how does this differ from Akira and SMA1000 exploitation, and what must an SMB or MSP do now?
- Field
- Initial Observations
- Value
- Huntress observed a distinct credential-stuffing campaign from July 25–27, 2026 affecting 92 accounts at 30 organizations and producing successful SonicWall VPN or firewall logins from five IP addresses. Huntress had not observed hands-on-keyboard follow-on activity when it published, did not identify the credential source, and did not attribute the campaign. This is separate from the 2025 MySonicWall cloud-backup theft, separate from supported Akira SSLVPN activity, and separate from the July 2026 INC/SMA1000 zero-day campaign.1, 2, 4
- Field
- Source Coverage
- Value
- Tier
- Tier 0 - Canonical registries
- Checked
- 0
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 0
- Tier
- Tier 1 - Primary authorities
- Checked
- 4
- Candidate Hits
- 4
- Planner Selected
- 4
- Not Used
- 0
- Tier
- Tier 2 - Technical / insurance research
- Checked
- 3
- Candidate Hits
- 3
- Planner Selected
- 3
- Not Used
- 0
- Tier
- Tier 3 - Corroborating news
- Checked
- 2
- Candidate Hits
- 2
- Planner Selected
- 2
- Not Used
- 0
- Tier
- Tier 4 - Community signal
- Checked
- 0
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 0
- Tier
- Tiers 5-8 - Custom / discovery / expansion
- Checked
- 0
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 0
- Tier
- Total retained evidence set
- Checked
- 9
- Candidate Hits
- 9
- Planner Selected
- 9
- Not Used
- 0
Tier Checked Candidate Hits Planner Selected Not Used Tier 0 - Canonical registries 0 0 0 0 Tier 1 - Primary authorities 4 4 4 0 Tier 2 - Technical / insurance research 3 3 3 0 Tier 3 - Corroborating news 2 2 2 0 Tier 4 - Community signal 0 0 0 0 Tiers 5-8 - Custom / discovery / expansion 0 0 0 0 Total retained evidence set 9 9 9 0
| Field | Value | ||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Whether stolen SonicWall cloud backups or credentials can help an attacker enter a fully patched, MFA-enabled on-premises firewall, and how the July 25–27, 2026 credential-stuffing campaign should be treated. | ||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is SonicWall, what happened July 25–27, what did the attackers achieve, where might credentials have come from, can configuration data explain apparent MFA bypass, how does this differ from Akira and SMA1000 exploitation, and what must an SMB or MSP do now? | ||||||||||||||||||||||||||||||||||||||||
| Initial Observations | Huntress observed a distinct credential-stuffing campaign from July 25–27, 2026 affecting 92 accounts at 30 organizations and producing successful SonicWall VPN or firewall logins from five IP addresses. Huntress had not observed hands-on-keyboard follow-on activity when it published, did not identify the credential source, and did not attribute the campaign. This is separate from the 2025 MySonicWall cloud-backup theft, separate from supported Akira SSLVPN activity, and separate from the July 2026 INC/SMA1000 zero-day campaign.1, 2, 4 | ||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
Three important SonicWall risk lanes overlap defensively but are not one attributed campaign.1, 2, 4
Observation Window
July 25–27
Three-day 2026 Huntress campaign window.
Organizations
30
Anonymized organizations affected in Huntress telemetry.
Accounts
92
26 + 34 + 32 affected accounts across the three days.
Campaign IPs
5
Source-backed infrastructure for hunting with time context.
- Evidence Lane
- July 25–27, 2026
- What Happened
- Credential stuffing with successful firewall/VPN logins.
- Boundary
- Unattributed; credential source and follow-on unknown.1
- Evidence Lane
- MySonicWall 2025
- What Happened
- State-sponsored actor obtained cloud configuration backups.
- Evidence Lane
- Akira SSLVPN history
- What Happened
- Separate ransomware access involving SonicWall SSLVPN, valid accounts, and configuration conditions.
| Evidence Lane | What Happened | Boundary |
|---|---|---|
| July 25–27, 2026 | Credential stuffing with successful firewall/VPN logins. | Unattributed; credential source and follow-on unknown.1 |
| MySonicWall 2025 | State-sponsored actor obtained cloud configuration backups. | No public link to July campaign or Akira.2, 8 |
| Akira SSLVPN history | Separate ransomware access involving SonicWall SSLVPN, valid accounts, and configuration conditions. | Does not attribute the other two lanes.4, 5, 7 |
The current trigger is credential abuse, not a new SonicWall exploit: five IPs achieved unauthorized logins during a three-day campaign affecting 30 organizations.1
The practical backup-to-network pivot is: steal the .EXP file, decode the readable configuration, map the exact exposed VPN and trust paths, combine that knowledge with separately usable credentials or trust material, establish a permitted firewall/VPN session, and inherit that session's authorized routes into the on-premises network. The backup improves targeting; it does not by itself prove password decryption or MFA defeat.2, 3, 4
Configuration theft could make later attacks more targeted, but public evidence does not prove it supplied the July credentials or connect the campaign to Akira.2, 9, 7
- Persona
- Executive / owner
- Primary Question
- Can a patched firewall still be entered?
- Persona
- SOC / IR
- Primary Question
- Which logins succeeded?
- Decision
- Correlate the five IPs, July 25–27 window, account/session records, portal use, internal access, and configuration changes.1
- Persona
- MSP
- Primary Question
- Which customers share the risk?
- Decision
- Scope every managed appliance and tenant independently; do not infer portfolio-wide compromise.1
- Persona
- Insurance / counsel
- Primary Question
- Is this vulnerability, access, or loss?
| Persona | Primary Question | Decision |
|---|---|---|
| Executive / owner | Can a patched firewall still be entered? | Yes through valid credentials or another configured trust path; require proof of identity, session, and downstream scope.1, 3 |
| SOC / IR | Which logins succeeded? | Correlate the five IPs, July 25–27 window, account/session records, portal use, internal access, and configuration changes.1 |
| MSP | Which customers share the risk? | Scope every managed appliance and tenant independently; do not infer portfolio-wide compromise.1 |
| Insurance / counsel | Is this vulnerability, access, or loss? | Separate credential attempts, successful authentication, post-authentication activity, data access, and operational impact.1, 9 |
- What happened: From July 25–27, 2026, Huntress observed broad credential stuffing that produced successful SonicWall VPN/firewall logins across 30 organizations.1
- How cloud backup can become on-premises access: A stolen .EXP backup can reveal the exact firewall, exposed VPN/management services, accounts, authentication backends, policies, routes, and trust relationships. If the attacker also obtains a working credential, session, shared secret, attacker-controlled TOTP enrollment, or another permitted path, the firewall can grant a legitimate-looking session whose assigned routes lead into the internal network. The backup is a targeting map, not automatic proof that encrypted secrets or MFA were defeated.2, 3, 4, 6
- What is known: Five source IPs, 92 affected accounts, successful logins, and the July 25–27 window are public. Actor identity, credential origin, and follow-on compromise were not established.1
- What to do: Hunt the five IPs and successful sessions, reset affected and backup-exposed trust material, invalidate sessions/TOTP, validate every authentication path, and scope internal access before declaring the appliance safe.1, 3
SonicWall firewalls and VPNs are the gatekeepers between the internet and internal business systems. On July 25–27, 2026, Huntress observed attackers testing stolen or reused credentials at scale and successfully logging into SonicWall services at 30 organizations. Because the activity used working accounts rather than a demonstrated software exploit, installing the latest firmware alone does not answer whether access occurred.1
The credential source is unknown, but the separate 2025 MySonicWall incident explains why a cloud backup can matter to an on-premises firewall. SonicWall says an .EXP backup is a full device snapshot. Its general configuration becomes readable after simple decoding and can expose the exact appliance, enabled internet-facing services, VPN policies, accounts, authentication servers, routes, network objects, and peer relationships. Passwords and keys remain individually encrypted, so possession is not the same as having every secret. Even so, the file removes much of an attacker's reconnaissance work and identifies precisely which credentials, portals, shared secrets, and trust paths are worth targeting. SonicWall's unusually broad reset matrix—local users, TOTP bindings, LDAP/RADIUS/TACACS secrets, IPSec keys, APIs, routing and management credentials—reflects that risk. No retained source proves these backups supplied the July 2026 credentials.2, 3
The next step requires usable access material or a weak path. An attacker can combine the configuration map with a separately stolen or reused password, unchanged VPN/shared secret, active session, or other configured trust. Rapid7 documented one concrete apparent-MFA-bypass mechanism in separate Akira cases: an attacker with a valid username and password could reach a publicly exposed Virtual Office portal and bind the attacker's own TOTP before using SSLVPN. SonicWall also warns that default LDAP-group configuration can authorize users more broadly than intended. Thus a fully patched appliance with 'MFA enabled' can still admit an attacker when the actual login path allows hostile enrollment, session reuse, over-broad authorization, or a service outside the expected MFA policy. Once the firewall grants the session, it can legitimately route that attacker toward the internal systems allowed for the identity or tunnel.4, 6, 3
Do not collapse the evidence into one Akira story. Akira has supported historical use of SonicWall SSLVPN and valid-account conditions, but the July credential-stuffing campaign is unattributed. SonicWall described the MySonicWall actor as state-sponsored, while the public evidence reviewed does not connect that incident to Akira. The INC/SMA1000 zero-day campaign affects a different SonicWall product and remains separate.1, 4, 7, 8
The decision is to treat successful authentication as a potential incident. Preserve logs, identify every affected account and session, complete the vendor credential-reset matrix, rebind TOTP, validate local and directory authorization, review configuration and internal access, and document whether the evidence supports attempts only, perimeter access, downstream compromise, data loss, or ransomware.1, 3
- Risk
- Valid-account entry
- Why It Matters
- Patching does not invalidate a working username, password, token, pre-shared key, or alternative authentication path.
- Risk
- Configuration intelligence
- Why It Matters
- A full snapshot can reveal topology, accounts, portals, authentication dependencies, VPN policy, and other targeting context even when secrets are encrypted.
- Risk
- Apparent MFA bypass
- Why It Matters
- The backup does not disable MFA. It can reveal where and how access is configured; an attacker who also has a valid password or other trust material may enroll TOTP through an exposed Virtual Office portal, use a service outside the expected MFA policy, reuse a session, or benefit from over-broad LDAP authorization.
| Risk | Why It Matters | Required Proof |
|---|---|---|
| Valid-account entry | Patching does not invalidate a working username, password, token, pre-shared key, or alternative authentication path. | Credential reset, session invalidation, account/config diff, and login-path review.1, 3 |
| Configuration intelligence | A full snapshot can reveal topology, accounts, portals, authentication dependencies, VPN policy, and other targeting context even when secrets are encrypted. | Treat exposed .EXP backups as sensitive and complete the vendor reset matrix.2, 3 |
| Apparent MFA bypass | The backup does not disable MFA. It can reveal where and how access is configured; an attacker who also has a valid password or other trust material may enroll TOTP through an exposed Virtual Office portal, use a service outside the expected MFA policy, reuse a session, or benefit from over-broad LDAP authorization. | Review TOTP creation and reset events, Virtual Office access on port 4433, default LDAP groups, active sessions, policy inheritance, and per-path MFA enforcement.4, 6, 3 |
- Date / Period
- September–October 2025 · MySonicWall
- Date / Period
- 2025 · Akira / SSLVPN lane
- Date / Period
- July 25, 2026
- Event / Meaning
- Huntress observed 26 affected accounts across six organizations.1
- Sources
- 1
- Date / Period
- July 26, 2026
- Event / Meaning
- Huntress observed 34 affected accounts across 16 organizations.1
- Sources
- 1
- Date / Period
- July 27, 2026
- Event / Meaning
- Huntress observed 32 affected accounts across eight organizations, completing the published July 25–27 campaign window.1
- Sources
- 1
- Date / Period
- 2026 · Marquis allegation
- Event / Meaning
- Marquis alleged that configuration data stolen from SonicWall cloud backup enabled attackers to circumvent its firewall and cause a ransomware incident; the conclusion is retained as a case-specific allegation, not a public Akira attribution or proof for the July campaign.9
- Sources
- 9
| Date / Period | Event / Meaning | Sources |
|---|---|---|
| September–October 2025 · MySonicWall | SonicWall disclosed unauthorized access to cloud-stored firewall configuration backups and ultimately said all cloud-backup users were affected; credential-reset guidance followed.2, 3 | 2, 3 |
| 2025 · Akira / SSLVPN lane | SonicWall and Rapid7 reporting linked separate Akira activity to SSLVPN access, CVE-2024-40766/legacy credential conditions, and authentication configuration risks.4, 5 | 4, 5 |
| July 25, 2026 | Huntress observed 26 affected accounts across six organizations.1 | 1 |
| July 26, 2026 | Huntress observed 34 affected accounts across 16 organizations.1 | 1 |
| July 27, 2026 | Huntress observed 32 affected accounts across eight organizations, completing the published July 25–27 campaign window.1 | 1 |
| 2026 · Marquis allegation | Marquis alleged that configuration data stolen from SonicWall cloud backup enabled attackers to circumvent its firewall and cause a ransomware incident; the conclusion is retained as a case-specific allegation, not a public Akira attribution or proof for the July campaign.9 | 9 |
- Phase
- Preserve before reset
| Phase | Action | Sources |
|---|---|---|
| Preserve before reset | Export logs and configuration evidence, note retention gaps, and record accounts, sessions, portals, authentication backends, and exposure windows before changing them.1, 3 | 1, 3 |
| Contain credential paths | Disable affected accounts, invalidate sessions, reset local/directory/service credentials, VPN pre-shared keys and API material, and rebind TOTP as applicable.3 | 3 |
| Scope beyond the appliance | Determine which internal routes, systems, identities, data, backups, and managed customers each successful session could reach.1, 4 | 1, 4 |
- Term
- Credential stuffing
- Meaning Here
- Automated or repeated testing of username/password pairs obtained elsewhere; distinct from exploiting a software flaw.1
- Sources
- 1
- Term
- .EXP configuration backup
| Term | Meaning Here | Sources |
|---|---|---|
| Credential stuffing | Automated or repeated testing of username/password pairs obtained elsewhere; distinct from exploiting a software flaw.1 | 1 |
| .EXP configuration backup | A SonicWall configuration snapshot containing sensitive topology and configuration context; credentials are individually encrypted, but the file still requires protected handling and broad remediation after exposure.2, 3 | 2, 3 |
| TOTP | Time-based one-time password used for MFA; binding and enrollment paths must be reviewed after credential exposure.4, 3 | 4, 3 |
- Behavior / ATT&CK
- Backup-to-on-premises pivot · evidence-bounded chain
- Campaign Mapping
- 1) Obtain the stolen .EXP preference file. 2) Decode its readable configuration to map enabled WAN services, VPN policies, accounts, authentication backends, routes, portals, and peer relationships. 3) Pair that map with a separately usable password, unchanged shared secret, active session, or weak trust path. 4) Where conditions allow, enroll attacker-controlled TOTP through an exposed Virtual Office portal or use a path outside the expected MFA policy. 5) Establish a legitimate-looking firewall/VPN session and inherit the internal routes permitted to that identity or tunnel. The backup alone does not prove secret decryption, MFA defeat, or downstream compromise.2, 3, 4, 6, 1
- Behavior / ATT&CK
- T1110.004 · Credential Stuffing
- Campaign Mapping
- High-volume use of candidate credentials against SonicWall services.1
- Sources
- 1
- Behavior / ATT&CK
- T1078 · Valid Accounts
- Campaign Mapping
- Successful authentication creates a trusted session despite current patch state.1
- Sources
- 1
- Behavior / ATT&CK
- T1133 · External Remote Services
| Behavior / ATT&CK | Campaign Mapping | Sources |
|---|---|---|
| Backup-to-on-premises pivot · evidence-bounded chain | 1) Obtain the stolen .EXP preference file. 2) Decode its readable configuration to map enabled WAN services, VPN policies, accounts, authentication backends, routes, portals, and peer relationships. 3) Pair that map with a separately usable password, unchanged shared secret, active session, or weak trust path. 4) Where conditions allow, enroll attacker-controlled TOTP through an exposed Virtual Office portal or use a path outside the expected MFA policy. 5) Establish a legitimate-looking firewall/VPN session and inherit the internal routes permitted to that identity or tunnel. The backup alone does not prove secret decryption, MFA defeat, or downstream compromise.2, 3, 4, 6, 1 | 2, 3, 4, 6, 1 |
| T1110.004 · Credential Stuffing | High-volume use of candidate credentials against SonicWall services.1 | 1 |
| T1078 · Valid Accounts | Successful authentication creates a trusted session despite current patch state.1 | 1 |
| T1133 · External Remote Services | VPN and firewall access can expose internal routes and services.1, 4 | 1, 4 |
- Question
- What is SonicWall?
- Answer
- A vendor of firewalls, VPNs, and secure-access products. These systems sit at the network perimeter and mediate trusted remote access.5
- Question
- What is new?
- Answer
- Huntress documented a July 25–27, 2026 credential-stuffing campaign with successful logins at 30 organizations from five IPs.1
- Question
- Was this a SonicWall vulnerability?
- Answer
- No vulnerability exploit was established. The observed mechanism was credential stuffing and valid-account login.1
- Question
- Was this Akira?
- Question
- How can a patched on-premises SonicWall with MFA still be entered?
- Answer
- Patching closes software flaws; it does not revoke valid accounts, sessions, VPN keys, directory secrets, or misconfigured trust paths. A stolen .EXP file can identify the precise exposed service and authentication design. If the attacker separately has a working password or other trust material, they may authenticate normally, enroll their own TOTP through an exposed Virtual Office portal, reuse a session, or use a path that does not enforce the MFA policy administrators expected. The resulting VPN session can then reach the internal routes assigned to that user or tunnel.2, 3, 4, 6
- Question
- Did the stolen .EXP file cause the July campaign?
| Question | Answer |
|---|---|
| What is SonicWall? | A vendor of firewalls, VPNs, and secure-access products. These systems sit at the network perimeter and mediate trusted remote access.5 |
| What is new? | Huntress documented a July 25–27, 2026 credential-stuffing campaign with successful logins at 30 organizations from five IPs.1 |
| Was this a SonicWall vulnerability? | No vulnerability exploit was established. The observed mechanism was credential stuffing and valid-account login.1 |
| Was this Akira? | No attribution is supported. Akira has separate SonicWall SSLVPN history, but neither this campaign nor the MySonicWall incident is publicly attributed to Akira.1, 4, 7 |
| How can a patched on-premises SonicWall with MFA still be entered? | Patching closes software flaws; it does not revoke valid accounts, sessions, VPN keys, directory secrets, or misconfigured trust paths. A stolen .EXP file can identify the precise exposed service and authentication design. If the attacker separately has a working password or other trust material, they may authenticate normally, enroll their own TOTP through an exposed Virtual Office portal, reuse a session, or use a path that does not enforce the MFA policy administrators expected. The resulting VPN session can then reach the internal routes assigned to that user or tunnel.2, 3, 4, 6 |
| Did the stolen .EXP file cause the July campaign? | Unknown. Configuration-derived targeting is plausible, and Marquis alleges such a path in its own incident, but no public evidence connects the July credentials to MySonicWall backups.2, 9 |
- Item
- July credential campaign
- Reference / Boundary
- No CVE; the source describes credential stuffing and valid-account login.1
- Sources
- 1
- Item
- CVE-2024-40766
| Item | Reference / Boundary | Sources |
|---|---|---|
| July credential campaign | No CVE; the source describes credential stuffing and valid-account login.1 | 1 |
| CVE-2024-40766 | Separate historical SonicWall/Akira defensive lane; a vulnerable or migration-affected estate requires its own evidence review.4, 5 | 4, 5 |
| SMA1000 CVEs | Excluded from this campaign because SMA1000 is a separate product and exploit chain.1 | 1 |
This public brief retains defensible detection and scoping observables, not raw attacker infrastructure or operational instructions. Validate against owned telemetry before blocking or attributing.
| Observable | Defender Use | Sources |
|---|---|---|
| 157.245.88[.]153 | Huntress July 25–27, 2026 campaign source IP; validate time, direction, and session outcome before blocking or attributing.1 | 1 |
| 162.243.31[.]111 | Huntress July 25–27, 2026 campaign source IP.1 | 1 |
| 167.71.150[.]1 | Huntress July 25–27, 2026 campaign source IP.1 | 1 |
| 209.97.151[.]148 | Huntress July 25–27, 2026 campaign source IP.1 | 1 |
| 64.227.15[.]20 | Huntress July 25–27, 2026 campaign source IP.1 | 1 |
| Hashes, malware filenames, and domains | None were published for this credential-stuffing campaign. Do not import Akira, MySonicWall, or SMA1000 indicators into this set.1 | 1 |
- Actor / Label
- July campaign operator
- Attribution Boundary
- Unattributed. The five IPs and successful logins do not establish actor identity.1
- Sources
- 1
- Actor / Label
- Akira
| Actor / Label | Attribution Boundary | Sources |
|---|---|---|
| July campaign operator | Unattributed. The five IPs and successful logins do not establish actor identity.1 | 1 |
| Akira | Relevant separate ransomware history involving SonicWall SSLVPN; not attributed to July credential stuffing or MySonicWall theft.4, 7 | 4, 7 |
| MySonicWall actor | SonicWall/Mandiant characterized the actor as state-sponsored; this does not identify the actor or connect it to Akira.8 | 8 |
- Audience
- Executive
| Audience | Decision-ready Point | Sources |
|---|---|---|
| Executive | This is an identity and trust-path incident, not simply a patching problem.1, 3 | 1, 3 |
| SOC | Successful authentication is the pivot: prove what the session reached and changed.1 | 1 |
| MSP | Shared management raises plausible blast radius, but every customer requires separate evidence.1 | 1 |
- Owner
- SOC / IR
- Time
- Now
- Decision / Evidence
- Hunt July 25–27 and adjacent retention for the five IPs, successful sessions, internal reach, and configuration changes.1
- Owner
- Identity / network
- Time
- 0–24 hours
- Decision / Evidence
- Disable affected accounts, reset credentials, invalidate sessions, rebind TOTP, and validate every authentication backend and portal.3
- Owner
- Executive / risk
- Time
- 0–48 hours
| Owner | Time | Decision / Evidence |
|---|---|---|
| SOC / IR | Now | Hunt July 25–27 and adjacent retention for the five IPs, successful sessions, internal reach, and configuration changes.1 |
| Identity / network | 0–24 hours | Disable affected accounts, reset credentials, invalidate sessions, rebind TOTP, and validate every authentication backend and portal.3 |
| Executive / risk | 0–48 hours | Require an evidence-backed finding that separates attempts, access, persistence, data, ransomware, and unresolved logging gaps.1, 9 |
- Technology / Trust Path
- SonicWall firewall / SSLVPN
- Technology / Trust Path
- Local and directory identity
| Technology / Trust Path | Risk / Defensive Priority | Sources |
|---|---|---|
| SonicWall firewall / SSLVPN | Perimeter access can expose trusted internal routes even on a patched appliance.1, 4 | 1, 4 |
| Local and directory identity | Local users, LDAP, RADIUS, TACACS, TOTP, portal, and group authorization must be validated together.3, 6 | 3, 6 |
| Cloud configuration backup | A stolen full snapshot can reduce attacker discovery cost and expose sensitive trust relationships even when individual secrets remain encrypted.2 | 2 |
- Tier
- Tier 1
- Tier
- Tier 2
- Tier
- Tier 3
- Tier
- Tiers 4–8
| Tier | Use |
|---|---|
| Tier 1 | SonicWall controls cloud-incident scope, backup sensitivity, and credential-reset guidance.2, 3, 5, 6 |
| Tier 2 | Huntress controls July campaign telemetry; Rapid7 controls its observed Akira/TOTP/LDAP path; Beazley supplies bounded insurance reconciliation.1, 4, 7 |
| Tier 3 | BleepingComputer corroborates the state-actor and Marquis disclosures but does not replace primary technical evidence.8, 9 |
| Tiers 4–8 | Used for discovery and cross-product reconciliation only; no social claim controls attribution or causation.1, 2 |
- Issue
- Three separate lanes
| Issue | How IntelliOS Handles It | Sources |
|---|---|---|
| Three separate lanes | July credential stuffing, MySonicWall backup theft, and Akira SSLVPN activity share defensive relevance but are not one proven campaign.1, 2, 4, 7 | 1, 2, 4, 7 |
| Marquis claim | Marquis says stolen configuration data enabled firewall circumvention in its incident. The statement is retained as a disclosed case conclusion, not independent public proof or an Akira link.9 | 9 |
| SMA1000 separation | The 2026 INC/SMA1000 campaign involves a different product and exploited vulnerabilities; its IOCs and attribution are not imported here.1 | 1 |
- Contributor
- Huntress
- Role in This Brief
- MDR provider controlling the July 25–27, 2026 campaign telemetry and indicators.1
- Sources
- 1
- Contributor
- SonicWall
| Contributor | Role in This Brief | Sources |
|---|---|---|
| Huntress | MDR provider controlling the July 25–27, 2026 campaign telemetry and indicators.1 | 1 |
| SonicWall | Product vendor controlling cloud-incident scope, backup sensitivity, and reset guidance.2, 3 | 2, 3 |
| Rapid7 | Incident-response research controlling its observed Akira, Virtual Office TOTP, and LDAP access findings.4 | 4 |
| Beazley Security | Insurance-focused source preserving the no-established-link boundary between Akira and MySonicWall.7 | 7 |
| Example | What It Shows / Boundary | Sources |
|---|---|---|
| July campaign victims | Thirty anonymized organizations; no named victim list was published.1 | 1 |
| Marquis | Named organization with a reported ransomware incident and litigation allegation involving SonicWall cloud backup; not proof of the July campaign or Akira attribution.9 | 9 |
Only explicitly public vendor or organization disclosures belong here. The rows below describe the public record and do not represent an affected-party list.
| Disclosure / Affected Set | Disclosure Boundary | Sources |
|---|---|---|
| July campaign victims | Thirty anonymized organizations; no named victim list was published.1 | 1 |
| Marquis | Named organization with a reported ransomware incident and litigation allegation involving SonicWall cloud backup; not proof of the July campaign or Akira attribution.9 | 9 |
The July 25–27, 2026 campaign is not a CVE or KEV event.
- Lane
- July credential stuffing
- Vulnerability Status
- No CVE established
- Interpretation
- Investigate valid credentials and authentication configuration, not only software versions.1
- Lane
- 2025 Akira SSLVPN
- Vulnerability Status
- Separate reporting includes CVE-2024-40766 and legacy credential conditions
- Lane
- 2026 SMA1000
- Vulnerability Status
- Separate exploited CVEs/product
- Interpretation
- Do not merge INC/UTA0533 evidence into SonicWall firewall credential events.1
| Lane | Vulnerability Status | Interpretation |
|---|---|---|
| July credential stuffing | No CVE established | Investigate valid credentials and authentication configuration, not only software versions.1 |
| 2025 Akira SSLVPN | Separate reporting includes CVE-2024-40766 and legacy credential conditions | Relevant historical defense lane; not attribution for July 2026.4, 5 |
| 2026 SMA1000 | Separate exploited CVEs/product | Do not merge INC/UTA0533 evidence into SonicWall firewall credential events.1 |
- Phase
- Credential access / initial access
- Evidence
- Credential stuffing and successful valid-account logins (T1110.004, T1078, T1133).
- Defense
- Rate/lockout controls, strong unique secrets, MFA-path validation, and session review.1
- Phase
- Post-authentication
- Evidence
- Not observed in Huntress's published campaign dataset.
- Defense
- Hunt internal routes, admin changes, data access, persistence, and security-control tampering.1
- Phase
- Impact
- Evidence
- No July-campaign ransomware impact established.
| Phase | Evidence | Defense |
|---|---|---|
| Credential access / initial access | Credential stuffing and successful valid-account logins (T1110.004, T1078, T1133). | Rate/lockout controls, strong unique secrets, MFA-path validation, and session review.1 |
| Post-authentication | Not observed in Huntress's published campaign dataset. | Hunt internal routes, admin changes, data access, persistence, and security-control tampering.1 |
| Impact | No July-campaign ransomware impact established. | Keep Akira/ransomware monitoring active without assigning attribution.1, 4 |
- Weight
- Controlling campaign evidence
- Source
- Huntress
- Controls
- July 25–27 dates, five IPs, counts, successful logins, unknown credential source, and no observed follow-on at publication.1
- Weight
- Controlling product evidence
- Source
- SonicWall
- Weight
- Qualified allegation
- Source
- Marquis / third-party investigation via BleepingComputer
- Controls
- Marquis's stated incident conclusion only; not universal proof or Akira attribution.9
| Weight | Source | Controls |
|---|---|---|
| Controlling campaign evidence | Huntress | July 25–27 dates, five IPs, counts, successful logins, unknown credential source, and no observed follow-on at publication.1 |
| Controlling product evidence | SonicWall | Cloud-backup scope, .EXP sensitivity, credential-reset actions, and separate SSLVPN guidance.2, 3, 5 |
| Qualified allegation | Marquis / third-party investigation via BleepingComputer | Marquis's stated incident conclusion only; not universal proof or Akira attribution.9 |
CARDS Campaign
2026 SonicWall Credential-Stuffing Campaign
Campaign-level July 25–27 evidence, five IPs, counts, successful-login scope, and attribution boundaries.
CARDS Threat Actor
Akira
Separate supported SonicWall SSLVPN/ransomware history with explicit non-attribution for the July and cloud incidents.
PANDA Flash Threat Intel Brief
INC Ransom Exploits SonicWall SMA1000 Zero Days
Separate product, vulnerability, IOC, and attribution lane.
PANDA Sector Risk Brief
Ransomware Targeting U.S. SMBs in 2026
Portfolio-level ransomware, access, insurance, and vendor-blast-radius context.
Published research notes
Public, read-only, source-backed context retained with this brief. No account or sign-in is required.
Confirmed
July 25–27, 2026 activity, five IPs, 92 affected accounts at 30 organizations, and successful SonicWall logins are source-backed.1
Unknown
Credential origin, operator identity, Akira relationship, cloud-backup relationship, and post-compromise impact remain unestablished.1, 7
Plausible but unproven
The defensible chain is backup theft → readable configuration and target mapping → separately usable credential/session/shared secret or weak authentication path → successful firewall/VPN session → access to the internal routes permitted for that identity or tunnel. The .EXP file does not by itself prove decryption of stored secrets, MFA defeat, July-campaign causation, or downstream compromise.2, 3, 4, 9
Campaign date precision
Every reference to the 2026 SonicWall Credential-Stuffing Campaign means the Huntress-observed July 25–27, 2026 window—not a month-long or open-ended campaign period.1
- #
- 1
- Tier
- Tier 2 - High-Value Research
- Publisher
- Huntress
- Published
- Checked Aug. 12, 2026
- Why Used
- Controlling source for July 25–27 activity, counts, successful logins, five IPs, credential-source uncertainty, and no observed follow-on at publication.
- #
- 2
- Tier
- Tier 1 - Primary Authority
- Publisher
- SonicWall
- Published
- Updated Oct. 28, 2025
- Why Used
- Controls cloud-backup incident scope, .EXP sensitivity, encryption description, and remediation priority.
- #
- 3
- Tier
- Tier 1 - Primary Authority
- Publisher
- SonicWall
- Published
- 2025
- Why Used
- Controls the reset matrix for local users, TOTP, directory services, VPN secrets, and API/other keys.
- #
- 4
- Tier
- Tier 2 - Primary Research
- Publisher
- Rapid7
- Published
- 2025
- Why Used
- Controls its observed Akira, Virtual Office TOTP enrollment, LDAP authorization, lateral movement, data theft, backup, and encryption findings.
- #
- 5
- Tier
- Tier 1 - Primary Authority
- Publisher
- SonicWall
- Published
- Aug. 2025
- Why Used
- Vendor boundary for separate SSLVPN/CVE-2024-40766 and migration-credential activity.
- #
- 6
- Tier
- Tier 1 - Primary Authority
- Publisher
- SonicWall
- Published
- 2025
- Why Used
- Controls the default LDAP authorization risk and intended group restriction guidance.
- #
- 7
- Tier
- Tier 2 - Insurance Research
- Publisher
- Beazley Security
- Published
- 2025
- Why Used
- Preserves the explicit no-established-link boundary between Akira and the MySonicWall backup incident.
- #
- 8
- Tier
- Tier 3 - Corroborating News
- Publisher
- BleepingComputer
- Published
- 2025
- Why Used
- Corroborates Mandiant/SonicWall state-actor and cloud-environment findings; does not identify the actor.
- #
- 9
- Tier
- Tier 3 - Corroborating News
- Publisher
- BleepingComputer
- Published
- Jan. 29, 2026
- Why Used
- Retains the named victim's third-party-investigation conclusion and litigation context without promoting it into universal causation or Akira attribution.
| # | Tier | Publisher | Published | Why Used | Source |
|---|---|---|---|---|---|
| 1 | Tier 2 - High-Value Research | Huntress | Checked Aug. 12, 2026 | Controlling source for July 25–27 activity, counts, successful logins, five IPs, credential-source uncertainty, and no observed follow-on at publication. | SonicWall Credential Stuffing Campaign |
| 2 | Tier 1 - Primary Authority | SonicWall | Updated Oct. 28, 2025 | Controls cloud-backup incident scope, .EXP sensitivity, encryption description, and remediation priority. | MySonicWall Cloud Backup File Incident |
| 3 | Tier 1 - Primary Authority | SonicWall | 2025 | Controls the reset matrix for local users, TOTP, directory services, VPN secrets, and API/other keys. | Essential Credential Reset |
| 4 | Tier 2 - Primary Research | Rapid7 | 2025 | Controls its observed Akira, Virtual Office TOTP enrollment, LDAP authorization, lateral movement, data theft, backup, and encryption findings. | Akira Ransomware Group Utilizing SonicWall Devices for Initial Access |
| 5 | Tier 1 - Primary Authority | SonicWall | Aug. 2025 | Vendor boundary for separate SSLVPN/CVE-2024-40766 and migration-credential activity. | Gen 7 and Newer SonicWall Firewalls SSLVPN Recent Threat Activity |
| 6 | Tier 1 - Primary Authority | SonicWall | 2025 | Controls the default LDAP authorization risk and intended group restriction guidance. | LDAP Configuration: SSLVPN Default User Groups Security Risk |
| 7 | Tier 2 - Insurance Research | Beazley Security | 2025 | Preserves the explicit no-established-link boundary between Akira and the MySonicWall backup incident. | Quarterly Threat Report: Third Quarter 2025 |
| 8 | Tier 3 - Corroborating News | BleepingComputer | 2025 | Corroborates Mandiant/SonicWall state-actor and cloud-environment findings; does not identify the actor. | SonicWall Says State-Sponsored Hackers Behind Security Breach |
| 9 | Tier 3 - Corroborating News | BleepingComputer | Jan. 29, 2026 | Retains the named victim's third-party-investigation conclusion and litigation context without promoting it into universal causation or Akira attribution. | Marquis Blames Ransomware Breach on SonicWall Cloud Backup Hack |
- Version
- v1.1
- Date
- Aug 12, 2026
- Changes
- Clarified the complete, evidence-bounded path from a stolen MySonicWall .EXP backup to targeted on-premises firewall/VPN access, apparent MFA bypass, and possible internal-network reach. Explicitly separates what the backup reveals from what still requires valid credentials, recoverable trust material, a misconfigured authentication path, or another access method.
- Version
- v1.0
- Date
- Aug 12, 2026
- Changes
- Initial 32-card release. Establishes the July 25–27, 2026 campaign, five Huntress IPs, successful-login scope, configuration-backup implications, Akira and SMA1000 separation, and Marquis allegation boundary.
| Version | Date | Changes |
|---|---|---|
| v1.1 | Aug 12, 2026 | Clarified the complete, evidence-bounded path from a stolen MySonicWall .EXP backup to targeted on-premises firewall/VPN access, apparent MFA bypass, and possible internal-network reach. Explicitly separates what the backup reveals from what still requires valid credentials, recoverable trust material, a misconfigured authentication path, or another access method. |
| v1.0 | Aug 12, 2026 | Initial 32-card release. Establishes the July 25–27, 2026 campaign, five Huntress IPs, successful-login scope, configuration-backup implications, Akira and SMA1000 separation, and Marquis allegation boundary. |
