**Cybersecurity firm urges immediate credential resets after attackers access backup files containing sensitive network information**
SonicWall has disclosed a significant security incident that exposed firewall configuration backup files stored in MySonicWall customer accounts. The breach has prompted the company to issue urgent warnings for users to reset their credentials immediately.
## What Happened
The attack targeted SonicWall’s cloud backup API service through a series of brute-force attacks on individual accounts. While the company has since blocked the attackers’ access and is working with cybersecurity experts and law enforcement, the damage may already be done.
According to SonicWall, the exposed configuration files contain critical information that could make it significantly easier for cybercriminals to exploit firewalls and gain unauthorized access to corporate networks.
## Scale of Impact
A SonicWall spokesperson confirmed that fewer than 5% of their firewall installations were affected by this breach. However, even this limited scope represents thousands of potentially compromised devices worldwide.
The exposed backup files contained encrypted passwords along with other sensitive data that could help attackers bypass security measures and infiltrate protected networks.
## Immediate Actions Required
SonicWall has published comprehensive guidance for administrators to minimize risks:
**Critical Steps:**
– Disable or restrict WAN access to device services before making changes
– Reset all user credentials, API keys, and authentication tokens
– Update VPN account passwords and service credentials
– Verify that password changes are also made with external providers (ISPs, email services, VPN peers)
The company emphasizes that credentials may need updating across multiple systems beyond just the SonicWall devices themselves.
## Broader Security Context
This incident follows recent concerns about SonicWall device vulnerabilities. In August, the company addressed reports of the Akira ransomware group exploiting Gen 7 firewalls, which was later confirmed to be related to a critical SSLVPN vulnerability (CVE-2024-40766) that has since been patched.
## Key Takeaways
This breach highlights the risks associated with cloud-based backup systems and the importance of:
– Regular credential rotation
– Multi-factor authentication implementation
– Prompt security patch application
– Comprehensive incident response planning
Organizations using SonicWall devices should immediately review their security configurations and implement the recommended credential resets to prevent potential network compromises.
