Dormant High impact Ransomware Checked 2d ago

INC ransomware breaches organizations through SonicWall VPN gateways

Researchers linked INC ransomware to attacks that used two previously unknown SonicWall SMA 1000 flaws to breach organizations in several countries. Attackers stole login data, planted malware, and tried to enter internal networks. No victim count is public.

Started
Jun 22, 2026
Latest activity
Aug 10, 2026
Attributed to
INC RansomwareLikely
Where
Australia, United States, UAE, Colombia, Switzerland
Sectors
Multiple sectors
Scale
Multiple private-sector and government victims across at least five countries

Current status

September 3 reporting covered a separate SonicWall exploit chain and did not link it to INC; no later confirmed activity in this campaign was found.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Resecurity linked the later activity to INC Ransomware, while CISA confirmed only that ransomware campaigns used the flaws.

Impact

Attackers gained full control of VPN gateways, installed backdoors, and stole credentials, session records, and one-time-code secrets. Researchers saw attempts to enter internal systems, but no broad outage or safety impact was reported.

What to do

SMA 1000 operators should patch, check for compromise, and rebuild affected devices.

Timeline

  1. Sep 3, 2026

    Cybersecurity Dive reported that the new SonicWall exploitation was not linked to a specific threat group and was separate from the July INC-linked campaign.

    Dormantcybersecuritydive.com
  2. Sep 2, 2026

    CISA added two different SonicWall SMA 1000 flaws to its exploited-vulnerabilities catalog. The update did not connect them to INC ransomware or add victims to this campaign.

    Dormantcisa.gov
  3. Aug 10, 2026

    CISA classified both SonicWall flaws as known to have been used in ransomware campaigns.

    bleepingcomputer.com
  4. Aug 1, 2026

    Resecurity linked later attacks to INC Ransomware and reported new victims across at least five countries.

    Activeresecurity.com
  5. Jul 17, 2026

    Volexity reported two compromised gateways at one unnamed customer, including malware, credential theft, and attempts to enter other systems.

    Activevolexity.com
  6. Jul 14, 2026

    SonicWall released fixes, and CISA added both exploited flaws to its priority patch list.

    Activecisa.gov
  7. Jun 22, 2026

    Volexity found the earliest sign of attackers compromising SonicWall SMA 1000 gateways through two previously unknown flaws.

    Activevolexity.com

Sources

Related reports