SonicWall Credential Stuffing Attack Hits 30 Organisations

Credential-stuffing spree compromises SonicWall VPN and firewall accounts

SonicWall Credential Stuffing Attack: What Happened

A major credential stuffing attack against SonicWall VPN and firewall portals was reported by Huntress beginning on 25 July 2026. This SonicWall credential stuffing attack rapidly compromised 92 valid user accounts in 30 organisations in less than 48 hours. The attack was broad and opportunistic, targeting any SonicWall device exposing remote access portals, rather than focusing on a particular sector or organisation type.

The campaign began with a sharp spike in successful logins detected by Huntress at 18:02:21 UTC on 25 July. Over the next two days, attackers achieved access to dozens of accounts using valid credentials, suggesting the use of previously compromised usernames and passwords harvested from sources such as stealer malware, historic breaches or leaked configuration files.

Timeline of the SonicWall Attack

  • 25 July 2026: 26 unique accounts across 6 organisations compromised, starting at 18:02 UTC.
  • 26 July 2026: 34 unique accounts across 16 organisations breached.
  • 27 July 2026: 32 unique accounts in 8 more organisations accessed. No further compromises recorded after this date.
  • 28 July 2026: Huntress publishes a public threat advisory with details of the campaign.
  • 29 July 2026: CyberScoop highlights the attack in a public report, confirming 92 accounts and 30 organisations affected.

During the event, Huntress observed no evidence of hands-on-keyboard activity or lateral movement, with attackers taking no further steps beyond initial access. This lack of post-compromise action suggests the campaign may be a preparatory stage for future operations, leaving compromised accounts in place for later exploitation.

Technical Details: Attack Method and Indicators

The SonicWall credential stuffing attack relied on automated validation of stolen or leaked credentials, not brute force. Attackers attempted to log in to remote access portals using valid combinations of usernames and passwords, most likely acquired from malware logs, earlier configuration leaks or past credential breaches involving SonicWall devices.

Attack Infrastructure and Scope

  • The campaign was traced to five DigitalOcean-hosted IP addresses used as the source for the login attempts:
    • 157.245.88.153
    • 162.243.31.111
    • 167.71.150.1
    • 209.97.151.148
    • 64.227.15.20
  • Huntress described the activity as a short, intense burst followed by sudden silence, matching patterns seen in other credential stuffing campaigns where adversaries rotate infrastructure to avoid detection.

SonicWall devices exposing VPN and firewall web portals were the targets. No particular model or firmware version was singled out as especially vulnerable, implying that the method would impact any organisation using default or previously compromised credentials on their SonicWall remote access portals.

Exploitation and Attribution

  • Attackers were unidentified at the time of reporting. The infrastructure used (DigitalOcean IPs and a suspicious ASN) points to a well-resourced actor with access to large credential dumps.
  • Huntress confirmed that attackers used valid credentials, not brute-force or exploitation of new software vulnerabilities. There is no evidence of a proof-of-concept exploit, malware deployment or hands-on-keyboard activity during the observed period.
  • The campaign stopped as abruptly as it began, a pattern often seen in credential validation activity conducted for future, staged attacks.

Broader Context: SonicWall Security and Past Incidents

This incident follows a series of high-profile SonicWall security events in recent years, some involving credential abuse and others leveraging zero-day vulnerabilities. In 2025, an undisclosed state-sponsored threat actor accessed SonicWall’s cloud environment and stole firewall configurations from all customers. In addition, SonicWall devices have been targeted by actively exploited zero-days and ransomware campaigns, with at least 17 vulnerabilities added to CISA’s known exploited vulnerabilities catalogue since 2021.

Although these previous incidents provide potential sources for the credentials abused in the July 2026 attacks, there is no confirmed link. The root cause for the specific credentials used remains unverified, but accumulation from malware logs or historic breaches is likely.

Current Status and Vendor Response

  • No SonicWall product advisory specific to this credential stuffing campaign had been issued as of 29 July 2026.
  • SonicWall stated it was investigating the activity but had not published new security guidance at the time of reporting.
  • Huntress’s visibility is limited to its own customer base, so the true scope may be broader.

Why This SonicWall Credential Stuffing Attack Matters

The campaign highlights the ongoing risk to organisations relying on SonicWall VPN and firewall portals for remote access, especially where multi-factor authentication (MFA) is not enforced. Attackers can bypass perimeter defences with valid credentials, gaining entry to critical infrastructure and potentially staging for ransomware or data theft operations.

UK small and midsized businesses, which often deploy SonicWall devices for perimeter security and remote connectivity, are particularly at risk if MFA is absent or misconfigured. Credential stuffing attacks can quickly compromise large numbers of accounts with minimal detection if robust controls are not in place.

What Organisations Should Do

  • Immediately enforce MFA on all SonicWall remote access and administrative accounts.
  • Audit authentication logs for anomalous or off-hours logins, disable affected accounts and rotate all potentially exposed credentials.
  • Ensure SonicWall devices are fully patched and hardened while the investigation continues.

Originally reported by cyberscoop.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call