logo

SonicWall says state-sponsored hackers behind September security breach

ID: fb98499f-c4f8-52c6-bd45-07e61fb244e1

STIX ID: report--fb98499f-c4f8-52c6-bd45-07e61fb244e1

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-05

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

SonicWall disclosed that state-sponsored threat actors accessed firewall configuration backup files stored in MySonicWall cloud accounts in September; Mandiant confirmed the activity was limited to those cloud backups and SonicWall reported no compromise of products, firmware, source code, or customer networks. The exposed files could contain credentials and tokens that would make it easier to exploit customer firewalls, prompting SonicWall to advise widespread credential and secret resets; the vendor also said the incident impacted customers using the cloud backup service and is unrelated to a separate Akira ransomware incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.