SonicWall Confirms Breach Exposing All Customer Firewall Configuration Backups
SonicWall, in collaboration with Mandiant, has concluded an investigation into a recent security incident involving cloud backup data.
SonicWall, in collaboration with Mandiant, has concluded an investigation into a recent security incident involving cloud backup data.
The investigation revealed unauthorized access to firewall configuration backup files for users of the MySonicWall cloud backup service. These files include encoded configuration settings and encrypted credentials. Despite the use of AES-256 encryption for credentials, the potential risk exists for targeted attacks due to the exposure of these files.
SonicWall has updated the MySonicWall portal with comprehensive lists of affected devices. Customers can find this information under Product Management > Issue List. Devices are categorized by impact priority:
Active - High Priority: Internet-facing units Active - Lower Priority: Non-internet-facing units Inactive: Devices that have not checked in for over 90 days
SonicWall is notifying all affected partners and customers and providing tools for assessment and remediation. Customers should log into their MySonicWall.com accounts to verify the presence of cloud backups for their registered firewalls.
SonicWall, in collaboration with Mandiant, has concluded an investigation into a recent security incident involving cloud backup data.
If backup fields are blank, devices are not at risk. If details are present, customers should:
Check the Issue List for flagged serial numbers, including device name, last download date, and impacted services. Prioritize remediation for Active – High Priority devices, followed by Active – Lower Priority devices. Review and reset credentials for services enabled at or before the backup timeframe.
SonicWall’s Essential Credential Reset guide provides containment and remediation steps.
Configuration backup files have the .EXP extension and represent a full snapshot of firewall settings. Locally exported EXP files are encoded, with credentials encrypted on modern SonicWall models. Cloud backup files are further encrypted and compressed before storage and are decrypted only when downloaded via HTTPS from MySonicWall.
SonicWall has implemented additional security measures in its cloud infrastructure and monitoring systems. The company is working with Mandiant to enhance detection controls and prevent unauthorized access.
For questions or assistance, customers should open a support case via the MySonicWall portal. SonicWall will provide further guidance to customers whose backup fields or serial numbers are not listed in the current Issue List, ensuring all users receive clear instructions for risk verification and response.
Based on reporting by GBHackers.
