Credential stuffing campaign hits 30 SonicWall customers in under 48 hours

A fast-moving, opportunistic attack wave compromised 92 SonicWall accounts across 30 organisations in 41 hours, with attackers showing no post-compromise activity yet — a pattern consistent with pre-positioning.

AI-generated illustration depicting incident for the story: Credential stuffing campaign hits 30 SonicWall customers in under 48 hours

Summary

  • Huntress identified a credential stuffing campaign that began Saturday and compromised 30 organisations and 92 unique SonicWall accounts within 41 hours.
  • The attacks appear opportunistic, targeting a broad range of SonicWall devices rather than any specific industry or organisation type.
  • No post-compromise activity has been observed, which analysts say is consistent with adversaries pre-positioning for future operations.
  • The campaign stopped as abruptly as it started — a pattern Huntress attributes to infrastructure rotation between attack waves.
  • SonicWall had not released a security advisory at press time and told CyberScoop it is still investigating.

A rapid, broad campaign

Huntress researchers disclosed on Tuesday that a credential stuffing campaign targeting SonicWall VPN and firewall accounts compromised 30 organisations and 92 unique user accounts over approximately 41 hours, beginning last Saturday. The attacks were described as broad and opportunistic — hitting various SonicWall device types without apparent focus on particular sectors or organisation sizes.

How the intrusions work

The attacks begin with what appear to be authorised logins: attackers validate credentials against remote access portals to gain entry. Huntress has not identified a definitive source for those credentials. Michael Tigges, principal tactical response analyst at Huntress, noted the credentials could stem from stealer malware logs, previously compromised SonicWall configuration files, or historic CVE exploitation that yielded more credentials than attackers could use at the time.

Silence after the burst

The campaign stopped on Monday, with no post-compromise activity observed across the affected accounts. Tigges said this fits a recognised campaign pattern: “A rash of compromise will break out, followed by silence until the adversary rotates infrastructure.” The absence of follow-on activity should not be read as good news — it is more consistent with adversaries quietly establishing footholds for later use.

Scope may be larger than reported

Huntress is careful to note that its visibility is limited to its own customer base. All 30 affected organisations were Huntress customers running SonicWall devices, meaning the true number of compromised organisations across the broader market is unknown and could be considerably higher. The attackers have not been identified.

SonicWall’s exposure is well documented

This campaign sits within a longer pattern of risk tied to SonicWall products. Seventeen vulnerabilities affecting SonicWall devices have been added to CISA’s Known Exploited Vulnerabilities catalogue since late 2021. Ten of those defects are associated with ransomware campaigns, including approximately 40 Akira ransomware attacks between mid-July and early August 2025. Earlier in 2025, a state-sponsored threat actor accessed SonicWall’s cloud environment and exfiltrated firewall configuration data from every customer — a breach that would have handed adversaries a significant credential and configuration advantage.

Edge devices remain the primary entry point

Tigges placed this incident in a broader operational context, noting that edge devices account for more than 70 per cent of active intrusions triaged by Huntress, including the majority of ransomware deployments. “With local network access, the sky is essentially the limit for most networks that do not have proper topology controls in place,” he said. Organisations that have not invested in secure remote access architecture and network segmentation are, in his view, likely to continue experiencing incidents in the period ahead.

Why it matters

For CISOs running SonicWall remote access infrastructure, this campaign represents a concrete and current threat, not a theoretical one. The credential stuffing method requires no zero-day; it succeeds because valid credentials exist in the wild — sourced from prior breaches, stealer logs, or the 2025 SonicWall cloud intrusion that exposed customer firewall configurations. The lack of post-compromise activity is not reassurance; it is a staging indicator. If your SonicWall accounts were touched and you have not already reviewed authentication logs for anomalous successful logins since last Saturday, that review is overdue. The wider pattern — 17 KEV entries, 10 linked to ransomware, repeated zero-day exploitation — signals that SonicWall-dependent remote access deserves elevated scrutiny in your risk register regardless of whether you were among the 30 confirmed victims.

What to do now

  • Audit SonicWall authentication logs for successful logins from unfamiliar IP addresses or geographies since last Saturday, paying particular attention to accounts that logged in but initiated no subsequent activity.
  • Review whether any accounts present on your SonicWall devices use credentials that may have been exposed in prior SonicWall-related breaches or stealer malware incidents, and force password resets accordingly.
  • Assess your network topology controls: if a compromised edge device grants broad lateral access, prioritise segmentation work to limit the blast radius of a future intrusion.
  • Ensure SonicWall firmware is current and cross-reference your deployed versions against CISA’s Known Exploited Vulnerabilities catalogue, particularly the 17 SonicWall entries added since late 2021.
  • Monitor SonicWall’s advisory channel for an official statement on this campaign, which the vendor indicated was still under investigation at press time, and factor that guidance into your response posture when it is released.

Sources