INC ransomware breaches organizations through SonicWall VPN gateways
Researchers linked INC ransomware to attacks that used two previously unknown SonicWall SMA 1000 flaws to breach organizations in several countries. Attackers stole login data, planted malware, and tried to enter internal networks. No victim count is public.
- Started
- Jun 22, 2026
- Latest activity
- Aug 10, 2026
- Attributed to
- INC RansomwareLikely
- Where
- Australia, United States, UAE, Colombia, Switzerland
- Sectors
- Multiple sectors
- Scale
- Multiple private-sector and government victims across at least five countries
Current status
September 3 reporting covered a separate SonicWall exploit chain and did not link it to INC; no later confirmed activity in this campaign was found.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Resecurity linked the later activity to INC Ransomware, while CISA confirmed only that ransomware campaigns used the flaws.
Impact
Attackers gained full control of VPN gateways, installed backdoors, and stole credentials, session records, and one-time-code secrets. Researchers saw attempts to enter internal systems, but no broad outage or safety impact was reported.
What to do
SMA 1000 operators should patch, check for compromise, and rebuild affected devices.
Timeline
-
Sep 3, 2026
Cybersecurity Dive reported that the new SonicWall exploitation was not linked to a specific threat group and was separate from the July INC-linked campaign.
Dormantcybersecuritydive.com -
Sep 2, 2026
CISA added two different SonicWall SMA 1000 flaws to its exploited-vulnerabilities catalog. The update did not connect them to INC ransomware or add victims to this campaign.
Dormantcisa.gov -
Aug 10, 2026
CISA classified both SonicWall flaws as known to have been used in ransomware campaigns.
bleepingcomputer.com -
Aug 1, 2026
Resecurity linked later attacks to INC Ransomware and reported new victims across at least five countries.
Activeresecurity.com -
Jul 17, 2026
Volexity reported two compromised gateways at one unnamed customer, including malware, credential theft, and attempts to enter other systems.
Activevolexity.com -
Jul 14, 2026
SonicWall released fixes, and CISA added both exploited flaws to its priority patch list.
Activecisa.gov -
Jun 22, 2026
Volexity found the earliest sign of attackers compromising SonicWall SMA 1000 gateways through two previously unknown flaws.
Activevolexity.com
Sources
- CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA Jul 14, 2026
- Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days Being Actively Exploited Rapid7 Jul 15, 2026
- Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation Volexity Jul 17, 2026
- From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain Resecurity Aug 1, 2026
- INC Ransomware chains two SonicWall SMA 1000 zero-days in attacks SC World Aug 3, 2026
- Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks SecurityWeek Aug 3, 2026
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs BleepingComputer Aug 10, 2026
- Known Exploited Vulnerabilities Catalog CISA Sep 2, 2026
- SonicWall urges immediate patching of chained vulnerabilities Cybersecurity Dive Sep 3, 2026 unverified
Related reports
- SonicWall SMA1000 zero-day lets attackers run code remotely Sep 2, 2026
- SonicWall zero-day flaws let attackers hijack firewalls Sep 2, 2026
- SonicWall SMA 1000 devices can be hacked remotely Sep 2, 2026
- Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks Aug 3, 2026
- SonicWall VPN appliances hit by ransomware attacks Aug 3, 2026
- SonicWall SMA 1000 zero-days used in ransomware attacks Aug 3, 2026