Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

Hackers Steal Sonicwall Cloud Backups

November 10, 2025
Reading Time: 4 mins read
in Incidents
Hackers Steal Sonicwall Cloud Backups

SonicWall recently revealed that a state-sponsored threat actor was responsible for the September security incident where firewall configuration files were stolen from its cloud backup service. Initially, the company reported that the attackers had exfiltrated backup files from less than 5% of its customers. However, in an October 8 update, SonicWall revised that figure, confirming that all firewall preference files stored using its cloud backup service were compromised and stolen in the attack.

The company warned that the stolen files contain highly sensitive data, specifically encrypted credentials and configuration data. SonicWall explicitly cautioned that attackers could leverage this information to launch targeted attacks against impacted organizations. Consequently, the company strongly urged all customers to check their MySonicWall.com accounts to determine if their firewall backups were listed, as this would indicate their devices were at risk. Most critically, they advised all affected customers to reset all passwords immediately, following the detailed steps in the accompanying containment and mitigation documentation.

To thoroughly investigate the breach, SonicWall engaged the cybersecurity firm Mandiant, and the company immediately notified all affected partners and customers about the incident. SonicWall announced this week that the investigation has been completed. The firm confirmed that the malicious activity was “isolated to the unauthorized access of cloud backup files from a specific cloud environment using an API call,” and explicitly stated that the attack did not impact any SonicWall products or firmware itself. Furthermore, it stressed that no other SonicWall systems, source code, or customer networks were disrupted or compromised.

SonicWall also took care to underline that this incident is unrelated to a recent wave of Akira ransomware intrusions that have been targeting SonicWall firewalls and other edge devices. The company affirmed it has “taken all current remediation actions recommended by Mandiant” and will continue to work with them and other third parties for the ongoing hardening of its network and cloud infrastructure. Despite the attack being isolated, the fact that a state-sponsored actor was involved highlights the serious nature of the intrusion.

The sensitive information contained within the stolen files poses a significant high risk for impacted organizations, making customer action paramount. This urgency is compounded by a separate warning issued in mid-October by Huntress, which flagged a widespread campaign targeting SonicWall SSL VPN accounts. That campaign, which the cybersecurity firm stated did not appear linked to the cloud backup incident, likely used valid credentials to compromise multiple businesses. Therefore, SonicWall customers are advised to take immediate and decisive action to secure their devices and reset credentials.

Reference:

  • State Hackers Steal Sonicwall Cloud Backups In Recent Cyber Attack
Tags: cyber incidentsCyber Incidents 2025Cyber threatsNovember 2025
ADVERTISEMENT

Related Posts

Defender Outage Disrupts Threat Alerting

Freedom Mobile Customer Data Breach Exposed

December 4, 2025
Defender Outage Disrupts Threat Alerting

Penn Phoenix Data Breach Oracle Hack Now

December 4, 2025
Defender Outage Disrupts Threat Alerting

Defender Outage Disrupts Threat Alerting

December 4, 2025
Sorbonne Staff Data Found On Dark Web

Indian Airports Hit By Cyber Attack

December 3, 2025
Sorbonne Staff Data Found On Dark Web

ChatGPT Down Worldwide Users Affected

December 3, 2025
Sorbonne Staff Data Found On Dark Web

Sorbonne Staff Data Found On Dark Web

December 3, 2025

Latest Alerts

Record DDoS Linked To Massive Botnet

RSC Bugs Let Hackers Run Remote Code Now

WordPress Elementor Addon Flaw Exploited

Lazarus APT Remote Worker Scheme Caught

Google Fixes 107 Android Flaws In Use

Npm Package Evades AI Security Tools

Subscribe to our newsletter

    Latest Incidents

    Freedom Mobile Customer Data Breach Exposed

    Penn Phoenix Data Breach Oracle Hack Now

    Defender Outage Disrupts Threat Alerting

    Indian Airports Hit By Cyber Attack

    ChatGPT Down Worldwide Users Affected

    Sorbonne Staff Data Found On Dark Web

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial