Credential-stuffing campaign hits SonicWall VPN and firewall accounts at 30 organizations

Attackers are trying stolen username-and-password pairs against SonicWall remote-access and firewall accounts, and Huntress says at least 30 organizations had successful logins. The campaign began July 25 and appears automated from five DigitalOcean-hosted IP addresses. Huntress said it had not yet seen follow-on hands-on intrusion activity, but the access shows real account compromise risk.
Why it matters: Organizations using SonicWall should review login activity, reset exposed passwords, enforce phishing-resistant multi-factor authentication where possible, and block or rate-limit abusive login attempts. Even without confirmed follow-on intrusion yet, successful logins mean attackers already got in.

Sources

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
SecurityWeek News 2026.07.31 100% relevant
The article establishes a distinct, concrete campaign targeting SonicWall accounts, with known start date, infrastructure, and victim count.
← Back to all stories