Article Details

Scrape Timestamp (UTC): 2025-10-09 13:52:41.447

Source: https://thehackernews.com/2025/10/hackers-access-sonicwall-cloud-firewall.html

Original Article Text

Click to Toggle View

Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks. SonicWall on Wednesday disclosed that an unauthorized party accessed firewall configuration backup files for all customers who have used the cloud backup service. "The files contain encrypted credentials and configuration data; while encryption remains in place, possession of these files could increase the risk of targeted attacks," the company said. It also noted that it's working to notify all partners and customers, adding it has released tools to assist with device assessment and remediation. The company is also urging users to log in and check for their devices. The development comes a couple of weeks after SonicWall urged customers to perform a credential reset after their firewall configuration backup files were exposed in a security breach impacting MySonicWall accounts. The list of impacted devices available on the MySonicWall portal has been assigned a priority level to help customers prioritize remediation efforts. The labels are as follows - It previously stated that the threat actors accessed backup firewall preference files stored in the cloud for less than 5% of its customers, while emphasizing that the credentials within those files were encrypted but that they also included "information that could make it easier for attackers to potentially exploit the related firewall." Users are advised to follow the steps below with immediate effect - SonicWall said in cases where customers have used the Cloud Backup feature but no Serial Numbers are shown or only some of the registered Serial Numbers are displayed, it will provide additional guidance in coming days.

Daily Brief Summary

DATA BREACH // SonicWall Data Breach Exposes Cloud Firewall Backup Files

SonicWall disclosed unauthorized access to firewall configuration backup files for customers using its cloud backup service, raising concerns about potential targeted attacks.

The compromised files contain encrypted credentials and configuration data, posing an increased risk despite the encryption.

SonicWall is actively notifying affected partners and customers and has released tools for device assessment and remediation.

Users are urged to log in and verify their devices, with priority levels assigned to assist in remediation efforts.

The breach affected less than 5% of SonicWall's customers, but the information in the files could facilitate exploitation of related firewalls.

SonicWall advises immediate action for users with cloud backup features, offering further guidance for those with incomplete serial number displays.

This incident follows a recent advisory for customers to reset credentials after exposure of firewall configuration backup files.