Network Security

All SonicWall Cloud Backup Users Had Firewall Configurations Stolen

In early September, hackers stole the firewall configuration backup files stored using the MySonicWall service.

SonicWall vulnerability

SonicWall on Wednesday announced that all customers who used its cloud backup service to store firewall configuration files were impacted by a recent data breach.

The incident occurred in early September and was disclosed a couple of weeks later, when SonicWall said hackers had accessed the backup firewall preference files of less than 5% of its customers.

In an October 8 update, the company said the threat actors accessed the preference files of all firewalls that were configured to back up the files to the MySonicWall cloud backup service.

“The files contain encrypted credentials and configuration data; while encryption remains in place, possession of these files could increase the risk of targeted attacks,” SonicWall warns.

The company says it is in the process of notifying all affected partners and customers, and has released tools to aid with assessment and remediation efforts.

SonicWall has published a list of impacted devices to the MySonicWall portal, and customers can access it by navigating to Product Management > Issue List.

Advertisement. Scroll to continue reading.

Each device is identified as either ‘Active – High Priority’, meaning it is exposed to the internet, ‘Active – Lower Priority’, if the device is not exposed to the internet, or ‘Inactive’, if it has not pinged home for 90 days.

“We urge all partners and customers to log in and check for their devices. SonicWall has implemented additional security hardening measures and is working closely with Mandiant to further enhance its cloud infrastructure and monitoring systems,” the company notes.

All customers should log in to their MySonicWall.com accounts and check if there are cloud backups for their registered firewalls. If such backups exist, customers should check the device serial numbers to determine if the firewalls are at risk.

The company urges customers to reset all their passwords and to follow the steps described in its containment and mitigation documentation to resolve the issue.

Related: Akira Ransomware’s Exploitation of SonicWall Vulnerability Continues

Related: SonicWall Updates SMA 100 Appliances to Remove Overstep Malware

Related: DraftKings Warns Users of Credential Stuffing Attacks

Related: The Y2K38 Bug Is a Vulnerability, Not Just a Date Problem, Researchers Warn

Related Content

Data Breaches

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.

Data Breaches

Hackers stole personal, medical, and health insurance information from a company’s data center.

Data Breaches

Hackers stole personal information, medical records, and financial information from the organization’s server.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Data Breaches

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version