SonicWall Customers Face Urgent Password Reset After Hackers Breach Cloud Backups in Brute-Force Attack

# SonicWall Urges Password Resets After Cloud Backup Security Breach

**Network security firm SonicWall is advising customers to immediately reset their credentials following a cyberattack that exposed firewall configuration backup files stored in their MySonicWall cloud service.**

## What Happened

SonicWall recently discovered suspicious activity targeting their cloud backup service for firewalls. Unknown cybercriminals successfully accessed backup firewall configuration files for less than 5% of the company’s customers through a series of brute-force attacks.

While the credentials stored in these files were encrypted, the exposed information could potentially help attackers exploit the associated firewalls more easily. Fortunately, SonicWall reports no evidence that these files have been leaked online, and this was not a ransomware attack on their network infrastructure.

## Immediate Actions Required

SonicWall is urging all customers to take the following security measures:

**Account Verification:**
– Log into MySonicWall.com to check if cloud backups are enabled
– Verify whether your device serial numbers have been flagged as affected

**Security Containment:**
– Restrict WAN access to services
– Disable HTTP/HTTPS/SSH management access
– Turn off SSL VPN and IPSec VPN access
– Reset all firewall passwords and time-based authentication codes (TOTPs)
– Review system logs and recent configuration changes for suspicious activity

## SonicWall’s Response

The company is providing affected customers with fresh preference files containing enhanced security measures, including:
– Randomized passwords for all local user accounts
– Reset time-based authentication bindings
– New randomized IPSec VPN encryption keys

Customers should only use these replacement files if they represent their desired security settings.

## Broader Security Concerns

This incident highlights ongoing threats to SonicWall devices. The Akira ransomware group has been actively targeting unpatched SonicWall systems, exploiting a critical vulnerability (CVE-2024-40766) with a severity score of 9.3 out of 10.

Recent attacks have shown sophisticated techniques, including the use of exposed recovery codes to bypass multi-factor authentication and disable security monitoring tools, effectively blinding organizations’ defenses.

## Key Takeaway

Organizations should treat backup files and recovery codes with the same security level as privileged account passwords. Regular security audits and prompt patching of known vulnerabilities remain critical for maintaining robust cybersecurity defenses.

Share This Article