Decoding the world of cybersecurity

Stolen passwords unlock SonicWall accounts at 30 organisations

An automated credential-stuffing campaign produced successful unauthorised SonicWall logins at 30 organisations without exploiting a software vulnerability.

Stolen passwords unlock SonicWall accounts at 30 organisations
Summary
  • Huntress observed successful unauthorised logins involving 92 accounts at 30 organisations between 25 and 27 July.
  • Five DigitalOcean-hosted IP addresses were used in a broad automated credential-validation campaign.
  • Huntress had not observed subsequent hands-on-keyboard activity, although affected accounts, configurations, and device-held secrets require investigation.

An automated credential-stuffing campaign produced successful unauthorised logins to SonicWall firewalls and virtual private network services at 30 organisations, using valid account details rather than exploiting a newly disclosed software vulnerability.

Huntress said the activity began at approximately 18:02 UTC on 25 July and continued over the next two days. Its telemetry identified successful access involving 92 user accounts across the affected organisations.

The logins originated from five IP addresses hosted by DigitalOcean and targeted apparently unrelated environments. Huntress assessed the activity as a broad and opportunistic credential-validation campaign consistent with similar attacks against SonicWall services during 2025 and 2026.

No post-compromise hands-on-keyboard activity had been observed when the advisory was published. Successful authentication nevertheless confirms that the supplied credentials remained valid and that the attacker reached a protected remote-access or firewall service.

The accounts may have been tested for later use, transferred to another actor, or retained as verified entries within a larger credential collection. Absence of visible follow-on activity during the observation period does not establish that every authenticated session was harmless.

Applying a software patch will not remove access where an attacker already holds a working username and password. Responders need to identify which accounts logged in, whether multifactor authentication was enforced, what permissions were available, and whether the same credentials were used on other services.

Identity failure at the network edge

Firewalls and VPN appliances occupy a sensitive position because they control remote access and may store administrative credentials, certificates, configuration backups, pre-shared keys, dynamic DNS details, and connections to directory or monitoring services.

Credential stuffing exploits passwords previously exposed through another service or reused across multiple accounts. A password can meet an organisation’s complexity requirements while remaining unsafe because it has already appeared in a breach elsewhere.

Automated testing allows an attacker to validate large collections against internet-facing services at low cost. Cloud infrastructure can be created and replaced quickly, while broad blocking of hosting-provider networks may interfere with legitimate traffic.

Multifactor authentication can prevent a stolen password from completing the login, but coverage must include every remote and administrative path. Legacy clients, emergency accounts, service identities, and contractor access can preserve exceptions through which the same credentials continue to work.

Huntress recommends restricting internet-facing management and remote access where possible, disabling affected accounts, resetting device secrets, reviewing recent authentication and configuration activity, and enforcing multifactor authentication across administrative and remote accounts.

The company also advises rotating credentials connected to Lightweight Directory Access Protocol, Remote Authentication Dial-In User Service, Terminal Access Controller Access-Control System Plus, wireless networks, Simple Network Management Protocol, external application programming interfaces, email, file transfer, and dynamic DNS.

Logs should be preserved before configuration changes reduce or overwrite the available evidence. Firewall records, identity-provider logs, endpoint telemetry, and network data can help establish whether an authenticated session progressed to internal connections, policy changes, credential access, or data transfer.

The investigation should extend beyond the account used against SonicWall. Reused credentials may remain valid in email, cloud, administrative, and supplier systems, while secrets stored on the appliance may provide further access even after the original password is reset.

Regulated organisations may also need to assess whether successful unauthorised access meets internal or statutory reporting thresholds. The decision will depend on the affected service, privileges, evidence of further action, and possible effect on data or operations.

The campaign succeeded against patched perimeter technology because the identity supplied to it was accepted as legitimate. Edge security remains dependent on unique credentials, complete multifactor coverage, restricted exposure, and records detailed enough to show what happened after authentication.

×