SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups
Recent incidents have highlighted vulnerabilities in SonicWall SSLVPN devices, following a major breach that exposed sensitive firewall data. These security challenges have affected multiple customer networks.
Recent incidents have highlighted vulnerabilities in SonicWall SSLVPN devices, following a major breach that exposed sensitive firewall data. These security challenges have affected multiple customer networks.
Commencing on Tue, Oct 4, 2025, unauthorized access attempts were observed across more than 100 accounts in 16 environments. These attempts involved valid credentials, possibly obtained through non-brute-force methods.
The attacks, believed to be linked to a recent cloud storage incident at SonicWall, involved rapid authentication and brief connections from IP address 202.155.8[.]73. In certain cases, attackers conducted network scans and attempted to access local Windows accounts, suggesting deeper reconnaissance activities.
SonicWall has confirmed that attackers accessed encrypted configuration backups through its MySonicWall cloud service. These backups contain critical data, including credentials and settings. Although encrypted, this information could facilitate targeted exploits if decrypted. Initially, it was reported that less than 5% of firewalls were impacted, but a subsequent update on Tue, Oct 10, 2025, revealed that all users of the backup feature were affected.
Recent incidents have highlighted vulnerabilities in SonicWall SSLVPN devices, following a major breach that exposed sensitive firewall data.
Organizations are advised to log into MySonicWall.com to verify device status and adhere to remediation protocols, including resetting exposed credentials.
Restrict WAN management and remote access where possible. Disable HTTP, HTTPS, SSH, SSL VPN, and inbound management interfaces until credentials are reset. Revoke and refresh local admin passwords, VPN pre-shared keys, LDAP or RADIUS bind credentials, wireless passphrases, and SNMP settings. Update external API keys, dynamic DNS configurations, SMTP or FTP accounts, and automation secrets linked to management systems. Implement enhanced logging for anomaly detection and forensic analysis. Gradually re-enable services post-resets while monitoring for unauthorized access. Enforce multi-factor authentication on all admin and remote accounts and apply least-privilege principles.
Huntress continues to monitor these threats and provides guidance through support resources, emphasizing the importance of proactive defense measures in the face of credential-based attacks.
Based on reporting by Cyber Security News.
